9.3
CVE-2008-4342
- EPSS 26.71%
- Veröffentlicht 30.09.2008 17:22:09
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Burnaware Technologies ≫ Burnaware Version2.1.3 Updateunknown Editionfree
Burnaware Technologies ≫ Burnaware Version2.1.3 Updateunknown Editionhome
Burnaware Technologies ≫ Burnaware Version2.1.3 Updateunknown Editionprofessional
Impressum ≫ Cdburnerxp Version4.2.1.976
Numedia Soft ≫ Numedia Dvd Burning Sdk Version1.008
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 26.71% | 0.96 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.