7.5
CVE-2007-4446
- EPSS 4.17%
- Veröffentlicht 21.08.2007 00:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:06
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Format string vulnerability in the server in Toribash 2.71 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the NICK command (client nickname) when entering a game.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.17% | 0.896 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://aluigi.org/poc/toribashish.zip
http://secunia.com/advisories/26507
http://securityreason.com/securityalert/3033
http://www.securityfocus.com/archive/1/477025/100/0/threaded
http://www.securityfocus.com/bid/25359