AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-4254

HIGH · CVSS 8.5 EPSS 22.06%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-12-10 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.5. It affects Microsoft. Its EPSS score suggests a 22.1% probability of exploitation in the next 30 days. It may be remotely exploitable.

CVE
CVE-2008-4254
Severity
HIGH
CVSS
8.5
EPSS
22.06%
Microsoft

Original NVD Description

Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized objects and corruption of the "system state," aka "Hierarchical FlexGrid Control Memory Corruption Vulnerability."