9.3
CVE-2008-1786
- EPSS 36.72%
- Published 16.04.2008 17:05:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop and Server Management r11.1 through r11.2 C2 allows remote attackers to execute arbitrary code via crafted function arguments.
Data is provided by the National Vulnerability Database (NVD)
Computer Associates ≫ Arcserve Backup Laptops And Desktops Versionr11.5
Computer Associates ≫ Desktop And Server Management Versionr11.1
Computer Associates ≫ Desktop And Server Management Versionr11.2
Computer Associates ≫ Desktop And Server Management Versionr11.2a
Computer Associates ≫ Desktop And Server Management Versionr11.2c1
Computer Associates ≫ Desktop And Server Management Versionr11.2c2
Computer Associates ≫ Desktop Management Suite Versionr11.2
Computer Associates ≫ Desktop Management Suite Versionr11.2a
Computer Associates ≫ Desktop Management Suite Versionr11.2c1
Computer Associates ≫ Desktop Management Suite Versionr11.2c2
Computer Associates ≫ Unicenter Asset Management Versionr11.1
Computer Associates ≫ Unicenter Asset Management Versionr11.2
Computer Associates ≫ Unicenter Asset Management Versionr11.2a
Computer Associates ≫ Unicenter Asset Management Versionr11.2c1
Computer Associates ≫ Unicenter Asset Management Versionr11.2c2
Computer Associates ≫ Unicenter Desktop Management Bundle Versionr11.1
Computer Associates ≫ Unicenter Desktop Management Bundle Versionr11.2
Computer Associates ≫ Unicenter Desktop Management Bundle Versionr11.2a
Computer Associates ≫ Unicenter Desktop Management Bundle Versionr11.2c1
Computer Associates ≫ Unicenter Desktop Management Bundle Versionr11.2c2
Computer Associates ≫ Unicenter Remote Control Versionr11.1
Computer Associates ≫ Unicenter Remote Control Versionr11.2
Computer Associates ≫ Unicenter Remote Control Versionr11.2a
Computer Associates ≫ Unicenter Remote Control Versionr11.2c1
Computer Associates ≫ Unicenter Remote Control Versionr11.2c2
Computer Associates ≫ Unicenter Software Delivery Versionr11.1
Computer Associates ≫ Unicenter Software Delivery Versionr11.2
Computer Associates ≫ Unicenter Software Delivery Versionr11.2a
Computer Associates ≫ Unicenter Software Delivery Versionr11.2c1
Computer Associates ≫ Unicenter Software Delivery Versionr11.2c2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 36.72% | 0.97 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.