CVE-2008-4922

Djvu Activex Control For Microsoft Office 2000 - Memory Corruption

Title source: rule

Description

Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16638
exploitdb WORKING POC VERIFIED
by Shahriyar Jalayeri · htmlremotewindows
https://www.exploit-db.com/exploits/6878
metasploit WORKING POC LOW
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/djvu_imageurl.rb

Scores

EPSS 0.6709
EPSS Percentile 98.6%

Details

CWE
CWE-119
Status published
Products (1)
djvu/activex_control_for_microsoft_office_2000
Published Nov 04, 2008
Tracked Since Feb 18, 2026