activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long string to this method, a remote attacker can execute arbitrary code in the context of the vulnerable process. Although the control is not marked safe for scripting, exploitation is possible via crafted HTML content in Internet Explorer under permissive security settings.
Metrics
Affected Vendors & Products
References
History
Sat, 22 Nov 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Activepdf
Activepdf webgrabber |
|
| CPEs | cpe:2.3:a:activepdf:webgrabber:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Activepdf
Activepdf webgrabber |
Tue, 16 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 02 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 30 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long string to this method, a remote attacker can execute arbitrary code in the context of the vulnerable process. Although the control is not marked safe for scripting, exploitation is possible via crafted HTML content in Internet Explorer under permissive security settings. | |
| Title | activePDF WebGrabber ActiveX Control Buffer Overflow | |
| Weaknesses | CWE-121 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-30T13:42:39.028Z
Updated: 2025-11-22T12:29:07.871Z
Reserved: 2025-08-28T16:51:12.840Z
Link: CVE-2008-20001
Updated: 2025-09-02T20:47:18.205Z
Status : Awaiting Analysis
Published: 2025-08-30T14:15:33.533
Modified: 2025-09-16T15:15:41.577
Link: CVE-2008-20001
No data.