« Volver al listado

CVE-2008-4825

Estado: ModificadaAlta (9.3)—

Multiple buffer overflows in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via a crafted (1) CIF, (2) C2D, or (3) GI file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-4825",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT-CNA@flexerasoftware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-04-01T18:00:00.217",
  "references": [
    {
      "url": "http://secunia.com/advisories/32415",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/secunia_research/2008-49/",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.ezbsystems.com/ultraiso/history.htm",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/502323/100/0/threaded",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/34325",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1021964",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0903",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/advisories/32415",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/secunia_research/2008-49/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ezbsystems.com/ultraiso/history.htm",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/502323/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34325",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1021964",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0903",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple buffer overflows in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via a crafted (1) CIF, (2) C2D, or (3) GI file."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de búfer en UltraISO v9.3.1.2633, y posiblemente otras versiones anteriores a v9.3.3.2685, permite a atacantes asistidos por usuario ejecutar código de su elección a través de ficheros (1) CIF, (2) C2D, o(3) GI manipulados."
    }
  ],
  "lastModified": "2026-06-16T22:58:37.407",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ezbsystems:ultraiso:9.3.1.2633:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "234765BD-26F3-44A6-A18B-BE724E619CB1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "PSIRT-CNA@flexerasoftware.com"
}