Lucene search

K
cveMitreCVE-2008-0647
HistoryFeb 07, 2008 - 9:00 p.m.

CVE-2008-0647

2008-02-0721:00:00
CWE-119
mitre
web.nvd.nist.gov
18
cve-2008-0647
hangameplugincn18
buffer overflow
ourgame glworld
activex control
remote code execution
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.163

Percentile

96.0%

Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
ourgame.comglworldMatch2.6.1.29
OR
ourgame.comhangameplugincn18_activex_control
VendorProductVersionCPE
ourgame.comglworld2.6.1.29cpe:2.3:a:ourgame.com:glworld:2.6.1.29:*:*:*:*:*:*:*
ourgame.comhangameplugincn18_activex_control*cpe:2.3:a:ourgame.com:hangameplugincn18_activex_control:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.163

Percentile

96.0%

Related for CVE-2008-0647