2.1
CVSSv2

CVE-2004-1500

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.

Vulnerable Product Search on Vulmon Subscribe to Product

monolith productions no one lives forever 1.0.004

monolith productions tron 2.0.1.42

monolith productions shogo 2.2

freeform interactive purge jihad 2.2.1

monolith productions blood 2.2.1

monolith productions no one lives forever 2.1.3

monolith productions kiss psycho circus 1.13

monolith productions global operations 2.1

monolith productions alien versus predator 2.1.0.9.6

monolith productions legends of might and magic 1.1

monolith productions sanity 1.0

monolith productions contract jack 1.1

monolith productions global operations 2.0

Exploits

source: wwwsecurityfocuscom/bid/11610/info Lithtech game engine is prone to multiple remote format-string vulnerabilities because of incorrect usage of 'printf()'-type functions Format specifiers can be supplied directly to vulnerable functions from external data A denial-of-service condition arises when a vulnerable server handles a ...