René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

101 lines
3.0 KiB
JSON

{
"id": "CVE-2008-6737",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-04-21T18:30:00.343",
"lastModified": "2017-08-17T01:29:31.897",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information."
},
{
"lang": "es",
"value": "Crysis v1.21 y anteriores permite a atacantes remotos obtener informaci\u00f3n sensible del jugador como su IP mediante el env\u00edo de un paquete \"keyexchange\" sin un paquete previo \"join\", lo que produce que Crysis env\u00ede un paquete desconectado incluyendo informaci\u00f3n del log no relacionada."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 7.8
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ea:crysis:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.21",
"matchCriteriaId": "6727C27C-0A21-40BB-AE96-8F056CE6FA8F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ea:crysis:1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "359F6C10-9244-4656-96C0-C4880D925A97"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ea:crysis:1.2:*:*:*:*:*:*:*",
"matchCriteriaId": "C4799ADB-A7EA-4044-AB66-9DC9330BC2BF"
}
]
}
]
}
],
"references": [
{
"url": "http://aluigi.altervista.org/adv/crysislog-adv.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/29720",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43087",
"source": "cve@mitre.org"
}
]
}