{"api_version":"1","generated_at":"2026-07-23T11:57:01+00:00","cve":"CVE-2008-4827","urls":{"html":"https://cve.report/CVE-2008-4827","api":"https://cve.report/api/cve/CVE-2008-4827.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4827","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4827"},"summary":{"title":"CVE-2008-4827","description":"Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and possibly other products, allow remote attackers to execute arbitrary code by adding many tabs, or adding tabs with long tab captions.","state":"PUBLISHED","assigner":"flexera","published_at":"2009-01-08 19:30:11","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/secunia_research/2008-52/","name":"http://secunia.com/secunia_research/2008-52/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Vulnerabilities - Secunia Research - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/33148","name":"http://www.securityfocus.com/bid/33148","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple Vendor SizerOne ActiveX Control 'AddTab' Method Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1021529","name":"http://securitytracker.com/id?1021529","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - SAP GUI Heap Overflow in 'sizerone.ocx' Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2008-53/","name":"http://secunia.com/secunia_research/2008-53/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Vulnerabilities - Secunia Research - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32609","name":"http://secunia.com/advisories/32609","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ComponentOne SizerOne CTab ActiveX Control Caption List Buffer Overflow - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2008-54/","name":"http://secunia.com/secunia_research/2008-54/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Vulnerabilities - Secunia Research - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/499830/100/0/threaded","name":"http://www.securityfocus.com/archive/1/499830/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/0036","name":"http://www.vupen.com/english/advisories/2009/0036","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32672","name":"http://secunia.com/advisories/32672","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SAP GUI TabOne ActiveX Control Caption List Buffer Overflow - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4879","name":"http://securityreason.com/securityalert/4879","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"TSC2 Help Desk CTab ActiveX Control Buffer Overflow - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/0037","name":"http://www.vupen.com/english/advisories/2009/0037","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47770","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47770","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47771","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47771","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47769","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47769","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32648","name":"http://secunia.com/advisories/32648","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"TSC2 Help Desk CTab ActiveX Control Caption List Buffer Overflow - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4827","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4827","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4827","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"componentone","cpe5":"sizerone","cpe6":"8.0.20081.140","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4827","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_gui","cpe6":"6.40","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4827","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_gui","cpe6":"7.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4827","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"tabone","cpe6":"7.0.0.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4827","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"servantix","cpe5":"tsc2_help_desk","cpe6":"4.18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:31:27.857Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20090107 Secunia Research: TSC2 Help Desk CTab ActiveX Control Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/499830/100/0/threaded"},{"name":"ADV-2009-0037","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/0037"},{"name":"ADV-2009-0036","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/0036"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2008-54/"},{"name":"sapgui-tabone-bo(47770)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47770"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2008-53/"},{"name":"33148","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/33148"},{"name":"sizerone-tab-bo(47771)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47771"},{"name":"32648","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32648"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2008-52/"},{"name":"1021529","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1021529"},{"name":"32609","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32609"},{"name":"4879","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4879"},{"name":"32672","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32672"},{"name":"tsc2-ctab-bo(47769)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47769"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-01-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and possibly other products, allow remote attackers to execute arbitrary code by adding many tabs, or adding tabs with long tab captions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"name":"20090107 Secunia Research: TSC2 Help Desk CTab ActiveX Control Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/499830/100/0/threaded"},{"name":"ADV-2009-0037","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/0037"},{"name":"ADV-2009-0036","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/0036"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2008-54/"},{"name":"sapgui-tabone-bo(47770)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47770"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2008-53/"},{"name":"33148","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/33148"},{"name":"sizerone-tab-bo(47771)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47771"},{"name":"32648","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32648"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2008-52/"},{"name":"1021529","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1021529"},{"name":"32609","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32609"},{"name":"4879","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4879"},{"name":"32672","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32672"},{"name":"tsc2-ctab-bo(47769)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47769"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2008-4827","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and possibly other products, allow remote attackers to execute arbitrary code by adding many tabs, or adding tabs with long tab captions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20090107 Secunia Research: TSC2 Help Desk CTab ActiveX Control Buffer Overflow","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/499830/100/0/threaded"},{"name":"ADV-2009-0037","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/0037"},{"name":"ADV-2009-0036","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/0036"},{"name":"http://secunia.com/secunia_research/2008-54/","refsource":"MISC","url":"http://secunia.com/secunia_research/2008-54/"},{"name":"sapgui-tabone-bo(47770)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47770"},{"name":"http://secunia.com/secunia_research/2008-53/","refsource":"MISC","url":"http://secunia.com/secunia_research/2008-53/"},{"name":"33148","refsource":"BID","url":"http://www.securityfocus.com/bid/33148"},{"name":"sizerone-tab-bo(47771)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47771"},{"name":"32648","refsource":"SECUNIA","url":"http://secunia.com/advisories/32648"},{"name":"http://secunia.com/secunia_research/2008-52/","refsource":"MISC","url":"http://secunia.com/secunia_research/2008-52/"},{"name":"1021529","refsource":"SECTRACK","url":"http://securitytracker.com/id?1021529"},{"name":"32609","refsource":"SECUNIA","url":"http://secunia.com/advisories/32609"},{"name":"4879","refsource":"SREASON","url":"http://securityreason.com/securityalert/4879"},{"name":"32672","refsource":"SECUNIA","url":"http://secunia.com/advisories/32672"},{"name":"tsc2-ctab-bo(47769)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47769"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2008-4827","datePublished":"2009-01-08T19:00:00.000Z","dateReserved":"2008-10-31T00:00:00.000Z","dateUpdated":"2024-08-07T10:31:27.857Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-01-08 19:30:11","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:componentone:sizerone:8.0.20081.140:*:*:*:*:*:*:*","matchCriteriaId":"ED7DA0C0-8757-468F-A2C0-5E32D20F1525"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:sap_gui:6.40:*:*:*:*:*:*:*","matchCriteriaId":"5BF9DC88-FD31-4536-94E9-47A9198826B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:sap_gui:7.10:*:*:*:*:*:*:*","matchCriteriaId":"62CFD60C-5DB5-4EFD-AFBB-773F6304FC5D"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:tabone:7.0.0.16:*:*:*:*:*:*:*","matchCriteriaId":"640CE1EE-F4F6-4625-AC34-171181DDAE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:servantix:tsc2_help_desk:4.18:*:*:*:*:*:*:*","matchCriteriaId":"107B41F9-8501-4D87-9184-613EAA7FDC8B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4827","Ordinal":"1","Title":"CVE-2008-4827","CVE":"CVE-2008-4827","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4827","Ordinal":"1","NoteData":"Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and possibly other products, allow remote attackers to execute arbitrary code by adding many tabs, or adding tabs with long tab captions.","Type":"Description","Title":"CVE-2008-4827"},{"CveYear":"2008","CveId":"4827","Ordinal":"2","NoteData":"2009-01-08","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4827","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}