7.5
CVSSv2

CVE-2008-0634

Published: 06/02/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote malicious users to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.

Vulnerable Product Search on Vulmon Subscribe to Product

sejoong namo activesquare 6

sejoong namo namoinstall.1 activex control 3.0.0.1

Exploits

<!-- Sejoong Namo ActiveSquare6 NamoInstallerdll BoF Exploit Written by wwwPlan-Scn Tested on Windows XP SP2(fully patched) Korean, IE6, NamoInstallerdll version 3,0,0,1 --> <html> <object classid="clsid:AF465549-1D22-4140-A273-386FA8877E0A" id="target"></OBJECT> <SCRIPT language="JavaScript"> // HeapS ...