Lucene search

K
cveMitreCVE-2008-3908
HistorySep 04, 2008 - 5:41 p.m.

CVE-2008-3908

2008-09-0417:41:00
CWE-119
mitre
web.nvd.nist.gov
27
cve-2008-3908
buffer overflows
princeton wordnet
wn 3.0
arbitrary code execution
privilege boundaries
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.019

Percentile

88.8%

Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.

Affected configurations

Nvd
Node
princeton_universitywordnetMatch3.0
VendorProductVersionCPE
princeton_universitywordnet3.0cpe:2.3:a:princeton_university:wordnet:3.0:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.019

Percentile

88.8%