CVE-2008-0912
high · 10Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long (1) username, (2) version, or (3) remote ID. NOTE: some of these details are obtained from third party information.
10
CVSS
15.6%
EPSS (exploit prob.)
97th
EPSS percentile
2008-02-22
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sybase | mobilink | <= 10.0.1.3629 |
| sybase | sql_anywhere | 10.0.1.3415 |
Check a specific version with /api/v1/cve/match.
References
- http://aluigi.altervista.org/adv/mobilinkhof-adv.txt
- http://secunia.com/advisories/29045
- http://securityreason.com/securityalert/3691
- http://www.securityfocus.com/archive/1/488409/100/0/threaded
- http://www.securityfocus.com/archive/1/490259/100/0/threaded
- http://www.securityfocus.com/bid/27914
- http://www.securitytracker.com/id?1019469
- http://www.vupen.com/english/advisories/2008/0626
- http://aluigi.altervista.org/adv/mobilinkhof-adv.txt
- http://secunia.com/advisories/29045
- http://securityreason.com/securityalert/3691
- http://www.securityfocus.com/archive/1/488409/100/0/threaded
- http://www.securityfocus.com/archive/1/490259/100/0/threaded
- http://www.securityfocus.com/bid/27914
- http://www.securitytracker.com/id?1019469
- http://www.vupen.com/english/advisories/2008/0626
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-0912