← back
CVE-2008-20001highCWE-121

activePDF WebGrabber ActiveX Control Buffer Overflow

36Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.5epss 1.1%
from disclosure to weapon0 days
Published on NVDAug 30
metasploitAug 26
exploitation probability
1.1%top 36% of all CVEs
observed exploitation
nono source reports it
activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long string to this method, a remote attacker can execute arbitrary code in the context of the vulnerable process. Although the control is not marked safe for scripting, exploitation is possible via crafted HTML content in Internet Explorer under permissive security settings.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
activePDF · WebGrabber