CVE-2008-0912
Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.6%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long (1) username, (2) version, or (3) remote ID. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 15.57% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- sybase/mobilink · sybase/sql anywhere
- Source
- cve@mitre.org
References
- http://aluigi.altervista.org/adv/mobilinkhof-adv.txtExploit
- http://secunia.com/advisories/29045Vendor Advisory
- http://securityreason.com/securityalert/3691
- http://www.securityfocus.com/archive/1/488409/100/0/threaded
- http://www.securityfocus.com/archive/1/490259/100/0/threaded
- http://www.securityfocus.com/bid/27914
- http://www.securitytracker.com/id?1019469
- http://www.vupen.com/english/advisories/2008/0626
- http://aluigi.altervista.org/adv/mobilinkhof-adv.txtExploit
- http://secunia.com/advisories/29045Vendor Advisory
- http://securityreason.com/securityalert/3691
- http://www.securityfocus.com/archive/1/488409/100/0/threaded
- http://www.securityfocus.com/archive/1/490259/100/0/threaded
- http://www.securityfocus.com/bid/27914
- http://www.securitytracker.com/id?1019469
- http://www.vupen.com/english/advisories/2008/0626
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.