Vulnerabilities > Ufo2000

DATE CVE VULNERABILITY TITLE RISK
2006-07-24 CVE-2006-3792 SQL Injection vulnerability in UFO2000
SQL injection vulnerability in ServerClientUfo::recv_packet in server_protocol.cpp in UFO2000 svn 1057 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving the packet.c_str function.
network
low complexity
ufo2000
7.5
2006-07-24 CVE-2006-3791 Remote vulnerability in UFO2000
The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a large keysize or valsize, which causes a crash when the resize function cannot allocate sufficient memory.
network
low complexity
ufo2000
5.0
2006-07-24 CVE-2006-3790 Remote vulnerability in UFO2000
The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a keysize or valsize that is inconsistent with the packet size, which leads to a buffer over-read.
network
low complexity
ufo2000
5.0
2006-07-24 CVE-2006-3789 Remote vulnerability in UFO2000
Multiple array index errors in the (1) recv_rules, (2) recv_select_unit, (3) recv_options, and (4) recv_unit_data functions in multiplay.cpp in UFO2000 svn 1057 allow remote attackers to execute arbitrary code and cause a denial of service (opponent crash) via certain packet data that specifies an out-of-bounds index.
network
low complexity
ufo2000
7.5
2006-07-24 CVE-2006-3788 Unspecified vulnerability in Ufo2000
Multiple buffer overflows in multiplay.cpp in UFO2000 svn 1057 allow remote attackers to execute arbitrary code via (1) a long unit name in Net::recv_add_unit,; (2) large values to Net::recv_rules, Net::recv_select_unit, Net::recv_options, and Net::recv_unit_data; and (3) a large mapdata GEODATA structure in Net::recv_map_data.
network
low complexity
ufo2000
7.5