{"api_version":"1","generated_at":"2026-07-23T11:46:38+00:00","cve":"CVE-2008-4384","urls":{"html":"https://cve.report/CVE-2008-4384","api":"https://cve.report/api/cve/CVE-2008-4384.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4384","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4384"},"summary":{"title":"CVE-2008-4384","description":"Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.","state":"PUBLISHED","assigner":"certcc","published_at":"2008-10-07 20:00:17","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/32140","name":"http://secunia.com/advisories/32140","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"iseemedia LPViewer ActiveX Control Multiple Buffer Overflow Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31604","name":"http://www.securityfocus.com/bid/31604","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"iseemedia 'LPControl.dll' LPViewer ActiveX Control Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2008/2749","name":"http://www.vupen.com/english/advisories/2008/2749","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45699","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45699","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/848873","name":"http://www.kb.cert.org/vuls/id/848873","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#848873 - iseemedia / Roxio / MGI Software LPViewer ActiveX control stack buffer overflows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4384","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4384","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4384","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iseemedia","cpe5":"lpviewer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4384","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mgi_software","cpe5":"lpviewer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4384","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"roxio","cpe5":"lpviewer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:17:09.825Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"32140","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32140"},{"name":"31604","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31604"},{"name":"lpviewer-lpcontrol-activex-bo(45699)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45699"},{"name":"VU#848873","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/848873"},{"name":"ADV-2008-2749","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2749"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-10-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"32140","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32140"},{"name":"31604","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31604"},{"name":"lpviewer-lpcontrol-activex-bo(45699)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45699"},{"name":"VU#848873","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/848873"},{"name":"ADV-2008-2749","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2749"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2008-4384","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"32140","refsource":"SECUNIA","url":"http://secunia.com/advisories/32140"},{"name":"31604","refsource":"BID","url":"http://www.securityfocus.com/bid/31604"},{"name":"lpviewer-lpcontrol-activex-bo(45699)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45699"},{"name":"VU#848873","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/848873"},{"name":"ADV-2008-2749","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2749"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2008-4384","datePublished":"2008-10-07T18:27:00.000Z","dateReserved":"2008-10-02T00:00:00.000Z","dateUpdated":"2024-08-07T10:17:09.825Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-10-07 20:00:17","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:iseemedia:lpviewer:*:*:*:*:*:*:*:*","matchCriteriaId":"8F6D98F4-A143-4D58-AB55-189EFD7DF1EE"},{"vulnerable":true,"criteria":"cpe:2.3:a:mgi_software:lpviewer:*:*:*:*:*:*:*:*","matchCriteriaId":"FF5732B5-E262-4638-8B5B-5B751A2A94F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:roxio:lpviewer:*:*:*:*:*:*:*:*","matchCriteriaId":"A5F79B6C-9359-4A48-8206-CE8FA305338A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4384","Ordinal":"1","Title":"CVE-2008-4384","CVE":"CVE-2008-4384","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4384","Ordinal":"1","NoteData":"Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.","Type":"Description","Title":"CVE-2008-4384"},{"CveYear":"2008","CveId":"4384","Ordinal":"2","NoteData":"2008-10-07","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4384","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}