CVE-2005-3486
Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other unspecified vectors.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 11.48% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- scorched 3d/scorched 3d
- Source
- cve@mitre.org
References
- http://aluigi.altervista.org/adv/scorchbugs-adv.txtExploit, Vendor Advisory
- http://marc.info/?l=full-disclosure&m=113095941031946&w=2
- http://secunia.com/advisories/17423
- http://www.gentoo.org/security/en/glsa/glsa-200511-12.xml
- http://www.securityfocus.com/bid/15292
- http://www.vupen.com/english/advisories/2005/2288
- http://aluigi.altervista.org/adv/scorchbugs-adv.txtExploit, Vendor Advisory
- http://marc.info/?l=full-disclosure&m=113095941031946&w=2
- http://secunia.com/advisories/17423
- http://www.gentoo.org/security/en/glsa/glsa-200511-12.xml
- http://www.securityfocus.com/bid/15292
- http://www.vupen.com/english/advisories/2005/2288
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.