{"api_version":"1","generated_at":"2026-07-23T12:22:08+00:00","cve":"CVE-2008-3878","urls":{"html":"https://cve.report/CVE-2008-3878","api":"https://cve.report/api/cve/CVE-2008-3878.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3878","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3878"},"summary":{"title":"CVE-2008-3878","description":"Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-09-02 15:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/31632","name":"http://secunia.com/advisories/31632","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Ultra Office ActiveX Control Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/6318","name":"https://www.exploit-db.com/exploits/6318","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ultra Shareware Office Control - ActiveX Control Remote Buffer Overflow - Windows remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30861","name":"http://www.securityfocus.com/bid/30861","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"504 Gateway Time-out","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44749","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44749","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4200","name":"http://securityreason.com/securityalert/4200","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - Ultra Office ActiveX Control Remote Buffer Overflow Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219826651.ff.php","name":"http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219826651.ff.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["URL Repurposed"],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html","name":"http://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","URL Repurposed"],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3878","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3878","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3878","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ultrashareware","cpe5":"ultra_office_control","cpe6":"2.0.2008.801","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:53:00.374Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html"},{"name":"6318","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/6318"},{"name":"31632","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31632"},{"name":"4200","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4200"},{"name":"uoc-ultraofficecontrol-bo(44749)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44749"},{"name":"30861","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30861"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219826651.ff.php"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-08-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html"},{"name":"6318","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/6318"},{"name":"31632","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31632"},{"name":"4200","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4200"},{"name":"uoc-ultraofficecontrol-bo(44749)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44749"},{"name":"30861","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30861"},{"tags":["x_refsource_MISC"],"url":"http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219826651.ff.php"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3878","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html","refsource":"MISC","url":"http://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html"},{"name":"6318","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/6318"},{"name":"31632","refsource":"SECUNIA","url":"http://secunia.com/advisories/31632"},{"name":"4200","refsource":"SREASON","url":"http://securityreason.com/securityalert/4200"},{"name":"uoc-ultraofficecontrol-bo(44749)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44749"},{"name":"30861","refsource":"BID","url":"http://www.securityfocus.com/bid/30861"},{"name":"http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219826651.ff.php","refsource":"MISC","url":"http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219826651.ff.php"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3878","datePublished":"2008-09-02T15:00:00.000Z","dateReserved":"2008-09-02T00:00:00.000Z","dateUpdated":"2024-08-07T09:53:00.374Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-09-02 15:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ultrashareware:ultra_office_control:2.0.2008.801:*:*:*:*:*:*:*","matchCriteriaId":"A81E8F3F-2263-4CBD-BA13-41E92D470A78"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3878","Ordinal":"1","Title":"CVE-2008-3878","CVE":"CVE-2008-3878","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3878","Ordinal":"1","NoteData":"Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.","Type":"Description","Title":"CVE-2008-3878"},{"CveYear":"2008","CveId":"3878","Ordinal":"2","NoteData":"2008-09-02","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3878","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}