5
CVE-2008-6712
- EPSS 7.4%
- Veröffentlicht 10.04.2009 22:00:00
- Zuletzt bearbeitet 16.06.2026 23:02:49
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a NULL pointer dereference.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.4% | 0.936 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
http://aluigi.org/poc/dontcrysis.txt
http://archives.neohapsis.com/archives/fulldisclosure/2008-06/0211.html
http://osvdb.org/46261
http://secunia.com/advisories/30675
http://www.securityfocus.com/archive/1/493385/100/0/threaded
http://www.securityfocus.com/bid/29759
https://exchange.xforce.ibmcloud.com/vulnerabilities/43126