// For flags

CVE-2008-3148

OllyDBG 1.10 and ImpREC 1.7f - Export Name Buffer Overflow

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary code via a crafted DLL file that contains a long string.

Desbordamiento de búfer basado en pila en (1) OllyDBG 1.10 y (2) ImpREC 1.7f permite a atacantes asistidos por usuario ejecutar código de su elección a través de un fichero DLL manipulado que contiene una cadena larga.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-07-11 CVE Reserved
  • 2008-07-11 CVE Published
  • 2024-02-25 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mackt
Search vendor "Mackt"
Imprec
Search vendor "Mackt" for product "Imprec"
1.7
Search vendor "Mackt" for product "Imprec" and version "1.7"
f
Affected
Ollydbg
Search vendor "Ollydbg"
Ollydbg
Search vendor "Ollydbg" for product "Ollydbg"
1.10
Search vendor "Ollydbg" for product "Ollydbg" and version "1.10"
-
Affected