René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

87 lines
2.5 KiB
JSON

{
"id": "CVE-2008-1127",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-03-03T23:44:00.000",
"lastModified": "2017-09-29T01:30:34.613",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format string specifiers in the user name, which is triggered when the game character is killed."
},
{
"lang": "es",
"value": "Vulnerabilidad de cadena de formato en la funci\u00f3n cryactio en Crysis 1.1.1.5879 permite a usuarios remotos autenticados ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de cadenas de formato especificadas en el nombre de usuario, lo cual es disparado cuando el car\u00e1cter game es eliminado."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 6.8,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-134"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:crytek:crysis:1.1.1.5879:*:*:*:*:*:*:*",
"matchCriteriaId": "950C6FBF-59CF-4C2C-B515-6DEBAEA241CA"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/28039",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0735",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/5201",
"source": "cve@mitre.org"
}
]
}