9.3
CVE-2008-0965
- EPSS 16.33%
- Published 08.08.2008 18:41:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.
Data is provided by the National Vulnerability Database (NVD)
Sun ≫ Opensolaris Editionsparc
Sun ≫ Opensolaris Editionx86
Sun ≫ Opensolaris Version <= build_snv_95
Sun ≫ Opensolaris Versionbuild_snv_01
Sun ≫ Opensolaris Versionbuild_snv_02
Sun ≫ Opensolaris Versionbuild_snv_13
Sun ≫ Opensolaris Versionbuild_snv_19
Sun ≫ Opensolaris Versionbuild_snv_22
Sun ≫ Opensolaris Versionbuild_snv_64
Sun ≫ Opensolaris Versionbuild_snv_88
Sun ≫ Opensolaris Versionbuild_snv_89
Sun ≫ Opensolaris Versionbuild_snv_91
Sun ≫ Opensolaris Versionbuild_snv_92
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 16.33% | 0.946 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.