CVE Feed

    Dashboard / CVE / CVE-2008-4255

    CVE-2008-4255

    Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."

    Published:Dec 10, 2008
    Last Modified:Apr 23, 2026
    EPS:Dec 10, 2008
    EPSS Score:0.65731
    CVSS Score:9.3

    Affected Products

    Vendor
    Microsoft
    Product
    Office Frontpage
    Vendor
    Microsoft
    Product
    Project
    Vendor
    Microsoft
    Product
    Visual Basic
    Vendor
    Microsoft
    Product
    Visual Foxpro
    Vendor
    Microsoft
    Product
    Visual Studio .net

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High