9.3

CVE-2008-1472

Exploit

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

Data is provided by the National Vulnerability Database (NVD)
Computer AssociatesDesktop Management Suite Versionr11.1 Updatec1
Computer AssociatesDesktop Management Suite Versionr11.1 Updatega
UnicenterAsset Management Versionr11.1 Updatea
UnicenterAsset Management Versionr11.1 Updatec1
UnicenterAsset Management Versionr11.1 Updatega
UnicenterAsset Management Versionr11.2
UnicenterAsset Management Versionr11.2 Updatea
UnicenterAsset Management Versionr11.2 Updatec1
UnicenterDesktop Management Bundle Versionr11.1 Updatea
UnicenterDesktop Management Bundle Versionr11.1 Updatec1
UnicenterDesktop Management Bundle Versionr11.1 Updatega
UnicenterDesktop Management Bundle Versionr11.2 Updatea
UnicenterDesktop Management Bundle Versionr11.2 Updatec1
UnicenterRemote Control Versionr11.1 Updatea
UnicenterRemote Control Versionr11.1 Updatec1
UnicenterRemote Control Versionr11.1 Updatega
UnicenterRemote Control Versionr11.2
UnicenterRemote Control Versionr11.2 Updatea
UnicenterRemote Control Versionr11.2 Updatec1
UnicenterSoftware Delivery Versionr11.1 Updatea
UnicenterSoftware Delivery Versionr11.1 Updatec1
UnicenterSoftware Delivery Versionr11.1 Updatega
UnicenterSoftware Delivery Versionr11.2
UnicenterSoftware Delivery Versionr11.2 Updatea
UnicenterSoftware Delivery Versionr11.2 Updatec1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 75.85% 0.989
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.