Vulnerabilities > CVE-2008-6712 - Remote Denial of Service vulnerability in EA Crysis 1.1/1.2

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
ea
exploit available

Summary

The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a NULL pointer dereference.

Vulnerable Configurations

Part Description Count
Application
Ea
3

Exploit-Db

descriptionCrysis 1.21 HTTP/XML-RPC Service Remote Denial of Service Vulnerability. CVE-2008-6712. Dos exploits for multiple platform
idEDB-ID:31931
last seen2016-02-03
modified2008-06-16
published2008-06-16
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/31931/
titleCrysis 1.21 - HTTP/XML-RPC Service Remote Denial of Service Vulnerability