← Vulnerability feed

Vulnerability record · CVE-2008-0470 · published 29 January 2008

CVE-2008-0470: Comodo antivirus vulnerability

Comodo · Comodo Antivirus

A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.

9.3 CVSS 2.0 High EPSS 31% · top 1.8%
9.3CVSS 2.0 base score
31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0470 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-0437HP Virtual Rooms ActiveX Control Buffer OverflowThe WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100 contains multiple buffer overflows in the AuthenticationURL, Po…EPSS 58%analysed9.3CVE-2008-0078Microsoft activex code injection vulnerabilityUnspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to ex…EPSS 29%9.3CVE-2008-0551Microsoft activex code injection vulnerabilityThe NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows rem…EPSS 30%9.3CVE-2007-6387Intuit bookkeeping memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks,…EPSS 38%4.3CVE-2012-1456Antivirus TAR parsers bypassed by appended ZIP fileMultiple antivirus products parse TAR archives in a way that lets a TAR file with an appended ZIP evade malware detection. An attacker can therefore …EPSS 100%analysed4.3CVE-2012-1459TAR parser malware detection bypass in multiple antivirus productsThe TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next en…EPSS 100%analysed4.3CVE-2012-1463Multiple antivirus ELF parsers bypassed via modified endianness fieldThe ELF file parser in a dozen antivirus products (AhnLab V3, Bitdefender, Quick Heal, Command, Comodo, eSafe, F-Prot, F-Secure, McAfee, Norman, nPro…EPSS 94%analysed4.3CVE-2012-1443RAR parser malware detection bypass in multiple antivirus enginesThe RAR file parser in dozens of antivirus products fails to correctly handle a RAR archive whose contents begin with an MZ character sequence, allow…EPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2008-0470), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.