Vulnerabilities > Toribash

DATE CVE VULNERABILITY TITLE RISK
2007-08-21 CVE-2007-4452 Denial-Of-Service vulnerability in Toribash
The client in Toribash 2.71 and earlier allows remote attackers to cause a denial of service (disconnection) via a long (1) emote or (2) SPEC command.
network
low complexity
toribash
5.0
2007-08-21 CVE-2007-4451 Multiple vulnerability in Toribash
The server in Toribash 2.71 and earlier on Windows allows remote attackers to cause a denial of service (continuous beep and server hang) via certain commands that contain many 0x07 or other invalid characters.
network
low complexity
toribash
5.0
2007-08-21 CVE-2007-4450 Improper Input Validation vulnerability in Toribash
The server in Toribash 2.71 and earlier does not properly handle long commands, which allows remote attackers to trigger a protocol violation in which data is sent to other clients without a required LF character, as demonstrated by a SAY command.
network
low complexity
toribash CWE-20
5.0
2007-08-21 CVE-2007-4449 Multiple vulnerability in Toribash
The client in Toribash 2.71 and earlier allows remote attackers to cause a denial of service (application hang) via a command without an LF character, as demonstrated by a SAY command.
network
low complexity
toribash
5.0
2007-08-21 CVE-2007-4448 Multiple vulnerability in Toribash
The server in Toribash 2.71 and earlier does not properly handle partially joined clients that are temporarily assigned the ID of -1, which allows remote attackers to cause a denial of service (daemon crash) via a GRIP command with the ID of -1.
network
low complexity
toribash
5.0
2007-08-21 CVE-2007-4447 Multiple vulnerability in Toribash
Multiple buffer overflows in the client in Toribash 2.71 and earlier allow remote attackers to (1) execute arbitrary code via a long game command in a replay (.rpl) file and (2) cause a denial of service (application crash) via a long SAY command that omits a required LF character; and allow remote Toribash servers to execute arbitrary code via (3) a long game command and (4) a long SAY command that omits a required LF character.
network
low complexity
toribash
7.5
2007-08-21 CVE-2007-4446 Multiple vulnerability in Toribash
Format string vulnerability in the server in Toribash 2.71 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the NICK command (client nickname) when entering a game.
network
low complexity
toribash
7.5