// For flags

CVE-2008-4254

 

Severity Score

8.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized objects and corruption of the "system state," aka "Hierarchical FlexGrid Control Memory Corruption Vulnerability."

Múltiples desbordamientos de enteros en el control ActiveX de Hierarchical FlexGrid (en el archivo mshflxgd.ocx) en Visual Basic versión 6.0 y Visual FoxPro versiones 8.0 SP1 y 9.0 SP1 y SP2, de Microsoft, permiten a los atacantes remotos ejecutar código arbitrario por medio de las propiedades diseñadas (1) Rows y (2) Cols de los métodos (a) ExpandAll y (b) CollapseAll, relacionados con el acceso a objetos inicializados incorrectamente y la corrupción del "system state," también se conoce como "Hierarchical FlexGrid Control Memory Corruption Vulnerability."

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-09-25 CVE Reserved
  • 2008-12-09 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-10-06 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Office Frontpage
Search vendor "Microsoft" for product "Office Frontpage"
2002
Search vendor "Microsoft" for product "Office Frontpage" and version "2002"
sp3
Affected
Microsoft
Search vendor "Microsoft"
Project
Search vendor "Microsoft" for product "Project"
2003
Search vendor "Microsoft" for product "Project" and version "2003"
sp3
Affected
Microsoft
Search vendor "Microsoft"
Project
Search vendor "Microsoft" for product "Project"
2007
Search vendor "Microsoft" for product "Project" and version "2007"
-
Affected
Microsoft
Search vendor "Microsoft"
Project
Search vendor "Microsoft" for product "Project"
2007
Search vendor "Microsoft" for product "Project" and version "2007"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Visual Basic
Search vendor "Microsoft" for product "Visual Basic"
6.0
Search vendor "Microsoft" for product "Visual Basic" and version "6.0"
runtime_extended_files
Affected
Microsoft
Search vendor "Microsoft"
Visual Foxpro
Search vendor "Microsoft" for product "Visual Foxpro"
8.0
Search vendor "Microsoft" for product "Visual Foxpro" and version "8.0"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Visual Foxpro
Search vendor "Microsoft" for product "Visual Foxpro"
9.0
Search vendor "Microsoft" for product "Visual Foxpro" and version "9.0"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Visual Foxpro
Search vendor "Microsoft" for product "Visual Foxpro"
9.0
Search vendor "Microsoft" for product "Visual Foxpro" and version "9.0"
sp2
Affected
Microsoft
Search vendor "Microsoft"
Visual Studio .net
Search vendor "Microsoft" for product "Visual Studio .net"
2002
Search vendor "Microsoft" for product "Visual Studio .net" and version "2002"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Visual Studio .net
Search vendor "Microsoft" for product "Visual Studio .net"
2003
Search vendor "Microsoft" for product "Visual Studio .net" and version "2003"
sp1
Affected