Unrated severityNVD Advisory· Published May 29, 2008· Updated Apr 23, 2026
CVE-2008-2499
CVE-2008-2499
Description
Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.
Affected products
2cpe:2.3:a:ibm:lotus_sametime:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:lotus_sametime:*:*:*:*:*:*:*:*range: <=7.5
- cpe:2.3:a:ibm:lotus_sametime:7.5.1:cf1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securityfocus.com/bid/29328nvdExploitThird Party AdvisoryVDB Entry
- secunia.com/advisories/30309nvdThird Party Advisory
- www-1.ibm.com/support/docview.wssnvdVendor Advisory
- www.securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2008/1595/referencesnvdThird Party Advisory
- www.zerodayinitiative.com/advisories/ZDI-08-028/nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/42575nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.