← Vulnerability feed

Vulnerability record · CVE-2008-0620 · published 6 February 2008

CVE-2008-0620: Sapgui memory buffer overflow vulnerability

Sap · Sapgui

SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LPD command, which causes the server to terminate.

10.0 CVSS 2.0 High EPSS 3.3% · top 11.9% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LPD command, which causes the server to terminate.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0620 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2007-4475Sapgui memory buffer overflow vulnerabilityStack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers t…EPSS 40%9.3CVE-2008-4387Sapgui code injection vulnerabilityUnspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unk…EPSS 16%7.8CVE-2006-7220Saplpd vulnerabilityUnspecified vulnerability in SAP SAPLPD and SAPSPRINT allows remote attackers to cause a denial of service (application crash) via a certain print jo…EPSS 1.2%7.5CVE-2016-10079Saplpd improper input validation vulnerabilitySAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.EPSS 6.5%7.5CVE-2008-0621SAP SAPLPD LPD command buffer overflow allows remote code executionSAPLPD 6.28 and earlier, shipped with SAP GUI 7.10 and SAPSprint before 1018, contains a buffer overflow triggered by long arguments to LPD commands …EPSS 73%analysed7.5CVE-2003-1035Sap r 3 vulnerabilityThe default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a b…EPSS 1.5%5.0CVE-2002-1579Sapgui vulnerabilitySAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unkn…EPSS 1.6%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV

Source: NIST National Vulnerability Database (record CVE-2008-0620), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.