Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2008-4038 | First vendor Publication | 2008-10-14 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4038 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:5787 | |||
Oval ID: | oval:org.mitre.oval:def:5787 | ||
Title: | SMB Buffer Underflow Vulnerability | ||
Description: | Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2008-4038 | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 4 | |
Os | 4 | |
Os | 4 | |
Os | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2008-10-15 | Name : SMB Remote Code Execution Vulnerability (957095) File : nvt/secpod_ms08-063_900053.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
49057 | Microsoft Windows SMB File Name Handling Remote Underflow |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows SMB Trans2 Find_First2 filename overflow attempt RuleID : 21529 - Revision : 9 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows SMB Search unicode andx Search filename size integer underf... RuleID : 14654 - Revision : 14 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows SMB Search andx Search filename size integer underflow attempt RuleID : 14653 - Revision : 14 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows SMB Search unicode andx Search filename size integer underf... RuleID : 14652 - Revision : 11 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows SMB Search andx Search filename size integer underflow attempt RuleID : 14651 - Revision : 11 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows SMB Search unicode Search filename size integer underflow a... RuleID : 14650 - Revision : 12 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows SMB Search Search filename size integer underflow attempt RuleID : 14649 - Revision : 16 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows SMB Search unicode Search filename size integer underflow a... RuleID : 14648 - Revision : 11 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows SMB Search Search filename size integer underflow attempt RuleID : 14647 - Revision : 11 - Type : OS-WINDOWS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2008-10-15 | Name : It is possible to crash the remote host due to a flaw in the 'server' service. File : smb_nt_ms08-063.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:13:16 |
|
2024-11-28 12:16:27 |
|
2023-12-07 21:28:06 |
|
2021-05-04 12:08:01 |
|
2021-04-22 01:08:22 |
|
2020-05-23 00:22:14 |
|
2019-03-18 12:01:49 |
|
2019-02-26 17:19:30 |
|
2018-10-13 00:22:43 |
|
2017-09-29 09:23:42 |
|
2017-08-08 09:24:22 |
|
2016-09-01 01:01:18 |
|
2016-06-28 17:17:49 |
|
2016-04-26 17:48:58 |
|
2014-02-17 10:46:33 |
|
2014-01-19 21:25:15 |
|
2013-05-11 00:25:37 |
|