CVE-2008-0623

Yahoo! Music Jukebox 2.2.2.056 - Stack-Based Buffer Overflow via AddImage Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2008-0623. PoCs published by exceed, anonymous, h07.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Yahoo! Music Jukebox 2.2 via the AddImage() method in the ActiveX control. It uses heap spraying to execute shellcode (calc.exe) when the vulnerable method is triggered.

Description

Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method.

Exploits (4)

exploitdb WORKING POC VERIFIED
by exceed · htmlremotewindows
https://www.exploit-db.com/exploits/5048

This exploit targets a buffer overflow vulnerability in Yahoo! Music Jukebox 2.2 via the AddImage() method in the ActiveX control. It uses heap spraying to execute shellcode (calc.exe) when the vulnerable method is triggered.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Yahoo! Music Jukebox 2.2 (datagrid.dll v2.2.2.56)
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer with the vulnerable ActiveX control installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by anonymous · phpremotewindows
https://www.exploit-db.com/exploits/5046

This exploit targets a vulnerability in the Aurigma Image Uploader ActiveX control (CVE-2008-0624) by triggering a heap-based buffer overflow via a maliciously crafted AddImage method call. The exploit uses a heap spray technique to achieve reliable code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Aurigma Image Uploader ActiveX Control (clsid:5F810AFC-BB5F-4416-BE63-E01DD117BD6C)
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · ActiveX control must be installed and enabled in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by h07 · htmldoswindows
https://www.exploit-db.com/exploits/5043

This is a proof-of-concept exploit for a buffer overflow vulnerability in Yahoo! Music Jukebox 2.2. It leverages the AddImage() method in an ActiveX control to trigger a crash via a crafted URL, demonstrating potential for arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Yahoo! Music Jukebox 2.2.2.056
No auth needed
Prerequisites: Victim must use Internet Explorer 6 · ActiveX controls must be enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
htmlremotewindows
https://www.exploit-db.com/exploits/5051

This is a functional exploit for a buffer overflow vulnerability in Yahoo! JukeBox's datagrid.dll AddButton() function. It uses heap spraying and shellcode to achieve remote code execution via a crafted HTML page.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Yahoo! JukeBox datagrid.dll version 2.2.2.56
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer 6 on Windows XP SP2
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019301
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28757
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/101676
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5046
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5048
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5043
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27590
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0396/references

Scores

EPSS 0.3858
EPSS Percentile 97.4%

Details

CWE
CWE-119
Status published
Products (1)
yahoo/music_jukebox 2.2.2.056
Published Feb 06, 2008
Tracked Since Feb 18, 2026