CVE Database
/

CVE-2008-4388

Back to search

CVE-2008-4388

Published: Jan 20, 2009

Modified: Sep 16, 2024

PUBLISHED

Description

The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and unspecified other methods.

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#194505
third-party-advisory
x_refsource_CERT-VN
33247
vdb-entry
x_refsource_BID
1021609
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now