CVE-2006-2399
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 5.7%
from disclosure to weapon0 days
Published on NVDMay 16
1st PoCMay 14
exploitation probability
5.7%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in the ServerNetworking::incoming_client_data function in servnet.cpp in Outgun 1.0.3 bot 2 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a data_file_request command with a long (1) type or (2) name string.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/1781⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://aluigi.altervista.org/adv/outgunx-adv.txthttp://secunia.com/advisories/20098http://securityreason.com/securityalert/898https://exchange.xforce.ibmcloud.com/vulnerabilities/26509http://www.securityfocus.com/archive/1/433932/100/0/threadedhttp://www.securityfocus.com/bid/17985http://www.vupen.com/english/advisories/2006/1796