← All CVEs

CVE-2008-6393

high · 10

PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.

10
CVSS
18.2%
EPSS (exploit prob.)
97th
EPSS percentile
2009-03-03
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
psi-impsi<= 0.12
psi-impsi0.1.0
psi-impsi0.8.6
psi-impsi0.8.7
psi-impsi0.9
psi-impsi0.9.1
psi-impsi0.9.2
psi-impsi0.9.3
psi-impsi0.11
jabberjabber_clientall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-6393