Vulnerabilities > Wesnoth > Wesnoth > 1.5.6

DATE CVE VULNERABILITY TITLE RISK
2009-03-12 CVE-2009-0366 Resource Management Errors vulnerability in Wesnoth
The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service via a large compressed WML document.
network
wesnoth CWE-399
4.3
2009-03-05 CVE-2009-0367 Permissions, Privileges, and Access Controls vulnerability in Wesnoth
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.
network
wesnoth CWE-264
critical
9.3