CVE-2008-4254 describes multiple integer overflow vulnerabilities within the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) affecting Microsoft Visual Basic 6.0, Visual FoxPro, and related products like Office FrontPage, Project, and Visual Studio .NET. This flaw allows remote authenticated attackers to execute arbitrary code by manipulating the Rows and Cols properties when calling the ExpandAll and CollapseAll methods, leading to memory corruption. With a CVSS score of 8.5 (High), this vulnerability has a network attack vector, medium attack complexity, and a complete impact on confidentiality, integrity, and availability. Despite its high severity and EPSS score, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2002CPE matchmatch criteria | cpe:2.3:a:microsoft:office_frontpage:2002:sp3:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:project:2003:sp3:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:project:2007:*:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:project:2007:sp1:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_basic:6.0:*:runtime_extended_files:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.