Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-4448

EPSS 1.32% · P80
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-4448

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The server in Toribash 2.71 and earlier does not properly handle partially joined clients that are temporarily assigned the ID of -1, which allows remote attackers to cause a denial of service (daemon crash) via a GRIP command with the ID of -1.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Toribash 拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
"Toribash是一款流行的格斗游戏。 Toribash 服务器在用户在加入服务器时,会为其分配ID -1,在调用ENTER命令之前不会再分配任何数据。攻击者可以将ID设置为-1加入到服务器并发送GRIP命令强制服务器处理请求,但包含客户端接收到值的结构为空,因此会失败: sscanf("0 0\n", "%i %i", &client.integer1, &client.integer2); 这里"0 0\n"是客户端所发送GRIP命令的第二部分(GRIP -1;0 0\n"),client.inte
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-4448

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-4448

Please Login to view more intelligence information

Same Patch Batch · n/a · 2007-08-21 · 29 CVEs total

CVE-2007-4216ZoneAlarm产品多个本地权限提升漏洞
CVE-2007-4452Toribash 拒绝服务漏洞
CVE-2007-4451Toribash 拒绝服务漏洞
CVE-2007-4450Toribash拒绝服务及远程代码执行漏洞
CVE-2007-4449Toribash 换行符分隔拒绝服务漏洞
CVE-2007-4447Toribash 客户端命令缓冲区溢出漏洞
CVE-2007-4446Toribash 专用服务器格式串漏洞
CVE-2007-4445rFactor 拒绝服务漏洞
CVE-2007-4444rFactor 缓冲区溢出漏洞
CVE-2007-4443Windows平台UCC dedicated 服务器Unreal引擎拒绝服务漏洞
CVE-2007-4442Unreal引擎 登录函数栈缓冲区溢出漏洞
CVE-2007-4441PHP'php_win32std.dll'缓冲区溢出
CVE-2007-4440Mercury Mail Transport System AUTH CRAM-MD5远程栈溢出漏洞
CVE-2007-4439Squirrelcart 'popup_window.php' PHP远程文件包含漏洞
CVE-2007-3618EMC Legato Networker nsrexecd.exe服务远程栈溢出漏洞
CVE-2007-4213Palm Treo智能手机远程拒绝服务漏洞
CVE-2005-2932ZoneAlarm产品多个本地权限提升漏洞
CVE-2007-4454Olate Download 'environment.php'代码执行漏洞
CVE-2007-4453vBulletin 多个跨站脚本攻击漏洞
CVE-2007-4464Total Commander Fileinfo插件CRLF 注入漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-4448

No comments yet


Leave a comment