9.3
CVE-2008-4342
- EPSS 17.2%
- Veröffentlicht 30.09.2008 17:22:09
- Zuletzt bearbeitet 16.06.2026 22:57:38
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Burnaware Technologies ≫ Burnaware Version2.1.3 Updateunknown Editionfree
Burnaware Technologies ≫ Burnaware Version2.1.3 Updateunknown Editionhome
Burnaware Technologies ≫ Burnaware Version2.1.3 Updateunknown Editionprofessional
Impressum ≫ Cdburnerxp Version4.2.1.976
Numedia Soft ≫ Numedia Dvd Burning Sdk Version1.008
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 17.2% | 0.967 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://retrogod.altervista.org/9sg_numedia_xpl.html
http://secunia.com/advisories/31936
http://secunia.com/advisories/31949
http://secunia.com/advisories/31950
http://secunia.com/advisories/32455
http://www.securityfocus.com/archive/1/497831/100/0/threaded
http://www.securityfocus.com/bid/31374
http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcq
http://www.vupen.com/english/advisories/2008/2663
https://exchange.xforce.ibmcloud.com/vulnerabilities/45330
https://www.exploit-db.com/exploits/6491