7.8

CVE-2005-3644

Exploit
PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp1
Microsoft ≫ Windows 2000 Update sp2
Microsoft ≫ Windows 2000 Update sp3
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Edition media_center
Microsoft ≫ Windows Xp Update gold Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition home
Microsoft ≫ Windows Xp Update sp1 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition home
Microsoft ≫ Windows Xp Update sp2 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition tablet_pc
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 42.3% 0.986
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://research.eeye.com/html/alerts/zeroday/20051116.html
http://secunia.com/advisories/17595
Vendor Advisory
http://securitytracker.com/id?1015233
http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2005/20051116
http://www.frsirt.com/exploits/20051117.Win_upnp_getdevicelist.c.php
Vendor Advisory
http://www.microsoft.com/technet/security/advisory/911052.mspx
Vendor Advisory
http://www.securiteam.com/exploits/6V00C15EKM.html
Exploit
http://www.securityfocus.com/bid/15460
https://www.exploit-db.com/exploits/1328