CVE-2008-1278

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
10/03/2008
Last modified:
09/04/2025

Description

The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of service (crash) via an invalid Accept-Charset header, which triggers a NULL pointer dereference. NOTE: the service is automatically restarted.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:remotelyanywhere:remotelyanywhere:*:*:server:*:*:*:*:* 8.0.668 (including)
cpe:2.3:a:remotelyanywhere:remotelyanywhere:*:*:workstation:*:*:*:*:* 8.0.668 (including)