{"api_version":"1","generated_at":"2026-07-23T07:37:36+00:00","cve":"CVE-2008-4391","urls":{"html":"https://cve.report/CVE-2008-4391","api":"https://cve.report/api/cve/CVE-2008-4391.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4391","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4391"},"summary":{"title":"CVE-2008-4391","description":"Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera before firmware 1.25 allows remote attackers to execute arbitrary code via long invalid arguments.","state":"PUBLISHED","assigner":"certcc","published_at":"2008-12-09 00:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/32665","name":"http://www.securityfocus.com/bid/32665","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Linksys WVC54GC 'NetCamPlayerWeb11gv2.ocx' ActiveX Control Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/WDON-7M2U52","name":"http://www.kb.cert.org/vuls/id/WDON-7M2U52","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"Linksys (A division of Cisco Systems) Information for VU#639345","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/639345","name":"http://www.kb.cert.org/vuls/id/639345","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","US Government Resource"],"title":"VU#639345 - Linksys WVC54GC NetCamPlayerWeb11gv2 ActiveX control stack buffer overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33032","name":"http://secunia.com/advisories/33032","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Linksys WVC54GC Information Disclosure and ActiveX Control Buffer Overflow - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4391","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4391","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4391","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"wvc54gc","cpe6":"1.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4391","vulnerable":"1","versionEndIncluding":"1.19","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"wvc54gc","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:17:09.453Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#639345","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/639345"},{"name":"32665","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/32665"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/WDON-7M2U52"},{"name":"33032","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33032"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera before firmware 1.25 allows remote attackers to execute arbitrary code via long invalid arguments."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-03-03T10:00:00.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"VU#639345","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/639345"},{"name":"32665","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/32665"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kb.cert.org/vuls/id/WDON-7M2U52"},{"name":"33032","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33032"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2008-4391","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera before firmware 1.25 allows remote attackers to execute arbitrary code via long invalid arguments."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#639345","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/639345"},{"name":"32665","refsource":"BID","url":"http://www.securityfocus.com/bid/32665"},{"name":"http://www.kb.cert.org/vuls/id/WDON-7M2U52","refsource":"CONFIRM","url":"http://www.kb.cert.org/vuls/id/WDON-7M2U52"},{"name":"33032","refsource":"SECUNIA","url":"http://secunia.com/advisories/33032"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2008-4391","datePublished":"2008-12-09T00:00:00.000Z","dateReserved":"2008-10-02T00:00:00.000Z","dateUpdated":"2024-08-07T10:17:09.453Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-12-09 00:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:wvc54gc:*:*:*:*:*:*:*:*","versionEndIncluding":"1.19","matchCriteriaId":"C882AB42-F04C-4968-A9C9-035A7411153E"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:wvc54gc:1.15:*:*:*:*:*:*:*","matchCriteriaId":"39AE4F03-2623-476F-BFBF-5D458432BAEC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4391","Ordinal":"1","Title":"CVE-2008-4391","CVE":"CVE-2008-4391","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4391","Ordinal":"1","NoteData":"Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera before firmware 1.25 allows remote attackers to execute arbitrary code via long invalid arguments.","Type":"Description","Title":"CVE-2008-4391"},{"CveYear":"2008","CveId":"4391","Ordinal":"2","NoteData":"2008-12-08","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4391","Ordinal":"3","NoteData":"2009-03-03","Type":"Other","Title":"Modified"}]}}}