7.8
CVSSv2

CVE-2005-3644

Published: 17/11/2005 Updated: 30/04/2019
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and previous versions, and possibly Windows XP SP1 and previous versions, allows remote malicious users to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 2000

microsoft windows xp

Exploits

/* * Author: Winny Thomas * Nevis Labs, Pune, INDIA * * Details: * While working on the exploit for MS05-047 i came across a condition where * a specially crafted request to upnp_getdevicelist would cause * servicesexe to consume memory to a point where the target machines virtual * memory gets exhausted This exploit is NOT sim ...