---
cve: "CVE-2008-0624"
severity: "LOW"
cvss: 3.1
epss: "7.6%"
vendor: "n/a"
kev: false
exploited: false
published: "2008-02-06 21:00:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T17:55:53+02:00"
---

# CVE-2008-0624

> 3.1 LOW · 🧪 PoC

## Beschreibung

Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddButton method, a different vulnerability than CVE-2008-0623.

## Exploit-Evidenz

- [EDB-5051 — Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow](https://www.exploit-db.com/exploits/5051) ✅
- [EDB-5046 — Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)](https://www.exploit-db.com/exploits/5046) ✅
- [EDB-5048 — Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)](https://www.exploit-db.com/exploits/5048) ✅
- [EDB-5043 — Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (PoC)](https://www.exploit-db.com/exploits/5043) ✅

## Referenzen

- <http://www.securityfocus.com/bid/27579>
- <http://secunia.com/advisories/28757>
- <http://www.kb.cert.org/vuls/id/101676>
- <http://www.vupen.com/english/advisories/2008/0396/references>
- <https://www.exploit-db.com/exploits/5051>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2008-0624) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
