CVE-2008-4254
published 2008-12-10CVE-2008-4254: Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and…
PriorityP355high8.5CVSS 2.0
AVNACMAuSCCICAC
EPSS
22.06%
97.4th percentile
Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized objects and corruption of the "system state," aka "Hierarchical FlexGrid Control Memory Corruption Vulnerability."
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office_frontpage | — | — |
| microsoft | project | — | — |
| microsoft | project | — | — |
| microsoft | visual_basic | — | — |
| microsoft | visual_foxpro | — | — |
| microsoft | visual_foxpro | — | — |
| microsoft | visual_studio_net | — | — |
| microsoft | visual_studio_net | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/secunia_research/2007-72/http://support.avaya.com/elmodocs2/security/ASA-2008-473.htmhttp://www.securityfocus.com/archive/1/499059/100/0/threadedhttp://www.securitytracker.com/id?1021369http://www.us-cert.gov/cas/techalerts/TA08-344A.htmlhttp://www.vupen.com/english/advisories/2008/3382https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-070https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5805http://secunia.com/secunia_research/2007-72/http://support.avaya.com/elmodocs2/security/ASA-2008-473.htmhttp://www.securityfocus.com/archive/1/499059/100/0/threadedhttp://www.securitytracker.com/id?1021369http://www.us-cert.gov/cas/techalerts/TA08-344A.htmlhttp://www.vupen.com/english/advisories/2008/3382https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-070https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5805
2008-12-10
Published