CVE-2008-4252
Summary
| CVE | CVE-2008-4252 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-12-10 14:00:00 UTC |
| Updated | 2018-10-12 21:48:00 UTC |
| Description | The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "DataGrid Control Memory Corruption Vulnerability." |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office Frontpage | 2002 | sp3 | All | All |
| Application | Microsoft | Office Frontpage | 2002 | sp3 | All | All |
| Application | Microsoft | Project | 2003 | sp3 | All | All |
| Application | Microsoft | Project | 2007 | All | All | All |
| Application | Microsoft | Project | 2007 | sp1 | All | All |
| Application | Microsoft | Project | 2003 | sp3 | All | All |
| Application | Microsoft | Project | 2007 | All | All | All |
| Application | Microsoft | Project | 2007 | sp1 | All | All |
| Application | Microsoft | Visual Basic | 6.0 | All | runtime_extended_files | All |
| Application | Microsoft | Visual Basic | 6.0 | All | runtime_extended_files | All |
| Application | Microsoft | Visual Foxpro | 8.0 | sp1 | All | All |
| Application | Microsoft | Visual Foxpro | 9.0 | sp1 | All | All |
| Application | Microsoft | Visual Foxpro | 9.0 | sp2 | All | All |
| Application | Microsoft | Visual Foxpro | 8.0 | sp1 | All | All |
| Application | Microsoft | Visual Foxpro | 9.0 | sp1 | All | All |
| Application | Microsoft | Visual Foxpro | 9.0 | sp2 | All | All |
| Application | Microsoft | Visual Studio .net | 2002 | sp1 | All | All |
| Application | Microsoft | Visual Studio .net | 2003 | sp1 | All | All |
| Application | Microsoft | Visual Studio .net | 2002 | sp1 | All | All |
| Application | Microsoft | Visual Studio .net | 2003 | sp1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft DataGrid ActiveX Control Memory Corruption Vulnerability | BID | www.securityfocus.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Microsoft Security Bulletin MS08-070 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| Microsoft Visual Basic DataGrid/FlexGrid/Heirarchival FlexGrid/Windows Common/Charts ActiveX Controls Let Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| ASA-2008-473 (ActiveX Controls) Could Allow Remote Code Execution (932349) | CONFIRM | support.avaya.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| US-CERT Technical Cyber Security Alert TA08-344A -- Microsoft Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.