7.8
CVE-2005-3644
- EPSS 42.3%
- Veröffentlicht 17.11.2005 11:02:00
- Zuletzt bearbeitet 16.06.2026 22:17:19
- Erkennungen
PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp1
Microsoft ≫ Windows 2000 Update sp2
Microsoft ≫ Windows 2000 Update sp3
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Edition media_center
Microsoft ≫ Windows Xp Update gold Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition home
Microsoft ≫ Windows Xp Update sp1 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition home
Microsoft ≫ Windows Xp Update sp2 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition tablet_pc
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 42.3% | 0.986 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
http://research.eeye.com/html/alerts/zeroday/20051116.html
http://secunia.com/advisories/17595
http://securitytracker.com/id?1015233
http://www.eeye.com/Resources/Security-Center/Research/Zero-Day-Tracker/2005/20051116
http://www.frsirt.com/exploits/20051117.Win_upnp_getdevicelist.c.php
http://www.microsoft.com/technet/security/advisory/911052.mspx
http://www.securiteam.com/exploits/6V00C15EKM.html
http://www.securityfocus.com/bid/15460
https://www.exploit-db.com/exploits/1328