CVE-2008-4922
Djvu Activex Control For Microsoft Office 2000 - Memory Corruption
Title source: ruleDescription
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16638
exploitdb
WORKING POC
VERIFIED
by Shahriyar Jalayeri · htmlremotewindows
https://www.exploit-db.com/exploits/6878
metasploit
WORKING POC
LOW
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/djvu_imageurl.rb
References (5)
Scores
EPSS
0.6709
EPSS Percentile
98.6%
Details
CWE
CWE-119
Status
published
Products (1)
djvu/activex_control_for_microsoft_office_2000
Published
Nov 04, 2008
Tracked Since
Feb 18, 2026