5
CVSSv2

CVE-2008-3680

Published: 14/08/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The decryption function in Flagship Industries Ventrilo 3.0.2 and previous versions allows remote malicious users to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784.

Vulnerable Product Search on Vulmon Subscribe to Product

flagship industries ventrilo 1.06

flagship industries ventrilo 2

flagship industries ventrilo 2.3

flagship industries ventrilo 2.3.2

flagship industries ventrilo 1.04

flagship industries ventrilo 1.05

flagship industries ventrilo 2.1.4

flagship industries ventrilo 2.2

flagship industries ventrilo 1.01

flagship industries ventrilo 1.03

flagship industries ventrilo 2.1.2

flagship industries ventrilo 2.1.3

flagship industries ventrilo 1

flagship industries ventrilo 2.1

flagship industries ventrilo 2.1.1

flagship industries ventrilo 3

flagship industries ventrilo 3.0.2

Exploits

NULL pointer in Ventrilo 302 githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/6237zip (2008-ventrilobotomyzip) # milw0rmcom [2008-08-13] ...