CVE-2008-0625

Yahoo! Music Jukebox 2.2.2.56 - Buffer Overflow via MediaGrid ActiveX AddBitmap Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0625. PoCs published by Elazar.

AI-analyzed exploit summary This is a buffer overflow exploit targeting the Yahoo! JukeBox MediaGrid ActiveX Control (mediagrid.dll) via the AddBitmap() method. It uses heap spraying and two Metasploit-generated shellcodes (calc.exe and bind shell) to achieve remote code execution.

Description

Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddBitmap method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Elazar · htmlremotewindows
https://www.exploit-db.com/exploits/5052

This is a buffer overflow exploit targeting the Yahoo! JukeBox MediaGrid ActiveX Control (mediagrid.dll) via the AddBitmap() method. It uses heap spraying and two Metasploit-generated shellcodes (calc.exe and bind shell) to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Yahoo! JukeBox MediaGrid ActiveX Control (mediagrid.dll) version 2.2.2.56
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer with the vulnerable ActiveX control installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/340860
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27578
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5052
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28757
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019298
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0396/references

Scores

EPSS 0.0810
EPSS Percentile 94.1%

Details

CWE
CWE-119
Status published
Products (1)
yahoo/music_jukebox 2.2.2.56
Published Feb 06, 2008
Tracked Since Feb 18, 2026