{"api_version":"1","generated_at":"2026-07-23T08:08:47+00:00","cve":"CVE-2008-3702","urls":{"html":"https://cve.report/CVE-2008-3702","api":"https://cve.report/api/cve/CVE-2008-3702.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3702","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3702"},"summary":{"title":"CVE-2008-3702","description":"Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-08-15 20:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44412","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44412","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30621","name":"http://www.securityfocus.com/bid/30621","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JComSoft 'AniGIF.ocx' ReadGIF and ReadGIF2 Methods ActiveX Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securityreason.com/securityalert/4159","name":"http://securityreason.com/securityalert/4159","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/6216","name":"https://www.exploit-db.com/exploits/6216","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Download Accelerator Plus DAP 8.6 - 'AniGIF.ocx' Buffer Overflow (PoC) - Windows dos Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3702","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3702","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3702","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jcomsoft","cpe5":"anigif","cpe6":"1.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3702","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jcomsoft","cpe5":"anigif","cpe6":"2.47","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3702","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"speedbit","cpe5":"download_accelerator_plus","cpe6":"8.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:45:19.197Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"6216","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/6216"},{"name":"4159","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4159"},{"name":"30621","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30621"},{"name":"jcomsoft-anigif-readgif-readgif2-bo(44412)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44412"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-08-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"6216","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/6216"},{"name":"4159","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4159"},{"name":"30621","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30621"},{"name":"jcomsoft-anigif-readgif-readgif2-bo(44412)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44412"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3702","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"6216","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/6216"},{"name":"4159","refsource":"SREASON","url":"http://securityreason.com/securityalert/4159"},{"name":"30621","refsource":"BID","url":"http://www.securityfocus.com/bid/30621"},{"name":"jcomsoft-anigif-readgif-readgif2-bo(44412)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44412"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3702","datePublished":"2008-08-15T20:06:00.000Z","dateReserved":"2008-08-15T00:00:00.000Z","dateUpdated":"2024-08-07T09:45:19.197Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-08-15 20:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jcomsoft:anigif:1.12:*:*:*:*:*:*:*","matchCriteriaId":"9C7CBCE0-29C7-413B-BAC8-A8BBB74F7F2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:jcomsoft:anigif:2.47:*:*:*:*:*:*:*","matchCriteriaId":"28C26193-9366-4E8C-B812-DF776DA29867"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:speedbit:download_accelerator_plus:8.6:*:*:*:*:*:*:*","matchCriteriaId":"6BD0BF9B-D984-4123-9D8B-7503E7954B74"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3702","Ordinal":"1","Title":"CVE-2008-3702","CVE":"CVE-2008-3702","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3702","Ordinal":"1","NoteData":"Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method.","Type":"Description","Title":"CVE-2008-3702"},{"CveYear":"2008","CveId":"3702","Ordinal":"2","NoteData":"2008-08-15","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3702","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}