VDB
CVE-2008-0985
CVE-2008-0985
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows remote attackers to execute arbitrary code via a crafted GIF file whose logical screen height and width are different than the actual height and width.
EPSS 4.59% · 91.2th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
4.59%
91.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| android_sdk | m3-rc37a |
Timeline
- Mar 4, 2008 PoC Published
- Mar 6, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- 28005 vdb
- 3727 third-party-advisory
- androidsdk-gifimagedecoderondecode-bo(40998) vdb
- http://www.coresecurity.com/?action=item&id=2148 url
- http://android-developers.blogspot.com/2008/03/android-sdk-update-m5-rc15-released.html url
- 20080304 CORE-2008-0124: Multiple vulnerabilities in Google's Android SDK mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2008-0985 advisory