← back
CVE-2008-3878

CVE-2008-3878

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 36%
from disclosure to weapon748 days
Published on NVDSep 2
1st PoC+748d
metasploitAug 27
exploitation probability
36%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.