{"api_version":"1","generated_at":"2026-07-23T08:39:38+00:00","cve":"CVE-2008-0956","urls":{"html":"https://cve.report/CVE-2008-0956","api":"https://cve.report/api/cve/CVE-2008-0956.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0956","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0956"},"summary":{"title":"CVE-2008-0956","description":"Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote attackers to execute arbitrary code via unspecified vectors.","state":"PUBLISHED","assigner":"certcc","published_at":"2008-06-12 02:32:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-032","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-032","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS16-011 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA08-162B.html","name":"http://www.us-cert.gov/cas/techalerts/TA08-162B.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA08-162B -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://backweb.com/news_events/press_releases/051608.php","name":"http://backweb.com/news_events/press_releases/051608.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["URL Repurposed"],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=121380194923597&w=2","name":"http://marc.info/?l=bugtraq&m=121380194923597&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/216153","name":"http://www.kb.cert.org/vuls/id/216153","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","US Government Resource"],"title":"VU#216153 - BackWeb Lite Install Runner ActiveX stack buffer overflows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/1792","name":"http://www.vupen.com/english/advisories/2008/1792","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42991","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42991","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/29558","name":"http://www.securityfocus.com/bid/29558","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BackWeb 'LiteInstActivator.dll' ActiveX Control Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/30598","name":"http://secunia.com/advisories/30598","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"BackWeb Lite Install Runner ActiveX Control Unspecified Buffer Overflows - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/1791","name":"http://www.vupen.com/english/advisories/2008/1791","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30625","name":"http://secunia.com/advisories/30625","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Logitech Desktop Messenger BackWeb ActiveX Control Unspecified Buffer Overflows - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0956","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0956","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"956","vulnerable":"1","versionEndIncluding":"8.1.1.86","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"backweb","cpe5":"backweb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"956","vulnerable":"1","versionEndIncluding":"2.55","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"logitech","cpe5":"desktop_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:01:40.085Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#216153","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/216153"},{"name":"ADV-2008-1791","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/1791"},{"name":"29558","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/29558"},{"name":"TA08-162B","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-162B.html"},{"name":"ADV-2008-1792","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/1792"},{"name":"30625","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30625"},{"name":"HPSBST02344","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=121380194923597&w=2"},{"name":"30598","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30598"},{"name":"SSRT080087","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=121380194923597&w=2"},{"name":"MS08-032","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-032"},{"name":"backweb-activex-liteinstactivator-bo(42991)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42991"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://backweb.com/news_events/press_releases/051608.php"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-06-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote attackers to execute arbitrary code via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"VU#216153","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/216153"},{"name":"ADV-2008-1791","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/1791"},{"name":"29558","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/29558"},{"name":"TA08-162B","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-162B.html"},{"name":"ADV-2008-1792","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/1792"},{"name":"30625","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30625"},{"name":"HPSBST02344","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=121380194923597&w=2"},{"name":"30598","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30598"},{"name":"SSRT080087","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=121380194923597&w=2"},{"name":"MS08-032","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-032"},{"name":"backweb-activex-liteinstactivator-bo(42991)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42991"},{"tags":["x_refsource_CONFIRM"],"url":"http://backweb.com/news_events/press_releases/051608.php"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2008-0956","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote attackers to execute arbitrary code via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#216153","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/216153"},{"name":"ADV-2008-1791","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/1791"},{"name":"29558","refsource":"BID","url":"http://www.securityfocus.com/bid/29558"},{"name":"TA08-162B","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA08-162B.html"},{"name":"ADV-2008-1792","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/1792"},{"name":"30625","refsource":"SECUNIA","url":"http://secunia.com/advisories/30625"},{"name":"HPSBST02344","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=121380194923597&w=2"},{"name":"30598","refsource":"SECUNIA","url":"http://secunia.com/advisories/30598"},{"name":"SSRT080087","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=121380194923597&w=2"},{"name":"MS08-032","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-032"},{"name":"backweb-activex-liteinstactivator-bo(42991)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42991"},{"name":"http://backweb.com/news_events/press_releases/051608.php","refsource":"CONFIRM","url":"http://backweb.com/news_events/press_releases/051608.php"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2008-0956","datePublished":"2008-06-12T01:30:00.000Z","dateReserved":"2008-02-25T00:00:00.000Z","dateUpdated":"2024-08-07T08:01:40.085Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-06-12 02:32:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:backweb:backweb:*:*:*:*:*:*:*:*","versionEndIncluding":"8.1.1.86","matchCriteriaId":"1F6C64B4-5C70-4407-85C5-9C378D9C6C93"},{"vulnerable":true,"criteria":"cpe:2.3:a:logitech:desktop_manager:*:*:*:*:*:*:*:*","versionEndIncluding":"2.55","matchCriteriaId":"390E21E8-0B91-40E7-9D1F-5FDB30BFDAE1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"956","Ordinal":"1","Title":"CVE-2008-0956","CVE":"CVE-2008-0956","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"956","Ordinal":"1","NoteData":"Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote attackers to execute arbitrary code via unspecified vectors.","Type":"Description","Title":"CVE-2008-0956"},{"CveYear":"2008","CveId":"956","Ordinal":"2","NoteData":"2008-06-11","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"956","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}