10
CVSSv2

CVE-2008-3892

Published: 03/09/2008 Updated: 01/11/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x prior to 5.5.8 build 108000, VMware Workstation 6.0.x prior to 6.0.5 build 109488, VMware Player 1.x prior to 1.0.8 build 108000, VMware Player 2.x prior to 2.0.5 build 109488, VMware ACE 1.x prior to 1.0.7 build 108880, VMware ACE 2.x prior to 2.0.5 build 109488, and VMware Server prior to 1.0.7 build 108231 allows remote malicious users to cause a denial of service (browser crash) or possibly execute arbitrary code via a call to the GuestInfo method in which there is a long string argument, and an assignment of a long string value to the result of this call. NOTE: this may overlap CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, or CVE-2008-3696.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware player

vmware ace

vmware server

vmware workstation

Exploits

----------------------------------------------------------------------------- VMWare COM API Buffer Overflow url: wwwvmwarecom/ Author: shinnai mail: shinnai[at]autistici[dot]org site: shinnainet This was written for educational purpose Use it at your own risk Author will be not responsible for any damage Tested on Wi ...