5

CVE-2006-1593

The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote attackers to cause a denial of service (crash) via an invalid player slot or item number, which causes an invalid memory access, possibly due to an invalid array index.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
X-doomX-doom Version1.06.07
ZdaemonZdaemon Version <= 1.08.01
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.58% 0.904
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://aluigi.altervista.org/adv/zdaebof-adv.txt
http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044775.html
http://secunia.com/advisories/19496
Vendor Advisory
http://secunia.com/advisories/19509
Vendor Advisory
http://www.securityfocus.com/archive/1/429521/100/0/threaded
http://www.securityfocus.com/bid/17340
http://www.vupen.com/english/advisories/2006/1198
Vendor Advisory
http://www.vupen.com/english/advisories/2006/1199
Vendor Advisory
http://securityreason.com/securityalert/662
https://exchange.xforce.ibmcloud.com/vulnerabilities/25593