9.3
CVSSv2

CVE-2008-6953

Published: 12/08/2009 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions prior to 1.7.1.59, allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long oovoo: URI.

Vulnerable Product Search on Vulmon Subscribe to Product

oovoo oovoo 1.7.1.35

Exploits

<?php /* ooVoo 17135 (URL Protocol) remote unicode buffer overflow poc by Nine:Situations:Group::bruiser tested against IE8b/xp sp3 9sg site: retrogodaltervistaorg/ software site: wwwoovoocom/ description: ooVoo is a startup video conferencing and instant messaging application, similar to Skype Video[1] ooVoo allows video ...