CVE-2008-0365
Estado: ModificadaAlta (7.2)—
Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.97%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-119
Referencias
- http://force.coresecurity.com/index.php?module=articles&func=display&aid=32
- http://securityreason.com/securityalert/3555
- http://www.coresecurity.com/?action=item&id=2025
- http://www.securityfocus.com/archive/1/486513/100/0/threaded
- http://www.securityfocus.com/bid/27341
- http://www.securitytracker.com/id?1019245
- http://www.vupen.com/english/advisories/2008/0242
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39758
- http://force.coresecurity.com/index.php?module=articles&func=display&aid=32
- http://securityreason.com/securityalert/3555
- http://www.coresecurity.com/?action=item&id=2025
- http://www.securityfocus.com/archive/1/486513/100/0/threaded
- http://www.securityfocus.com/bid/27341
- http://www.securitytracker.com/id?1019245
- http://www.vupen.com/english/advisories/2008/0242
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39758
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-0365",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-01-18T23:00:00.000",
"references": [
{
"url": "http://force.coresecurity.com/index.php?module=articles&func=display&aid=32",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3555",
"source": "cve@mitre.org"
},
{
"url": "http://www.coresecurity.com/?action=item&id=2025",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/486513/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27341",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1019245",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0242",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39758",
"source": "cve@mitre.org"
},
{
"url": "http://force.coresecurity.com/index.php?module=articles&func=display&aid=32",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3555",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.coresecurity.com/?action=item&id=2025",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/486513/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27341",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1019245",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0242",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39758",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module."
},
{
"lang": "es",
"value": "Múltiples desbordamientos de búfer en CORE FORCE versiones anteriores a 0.95.172 permiten a usuarios locales provocar una denegación de servicio (caída de aplicación) y posiblemente ejecutar código de su elección en contexto de núcleo mediante argumentos manipulados en (1) funciones IOTCL en el módulo Firewall ó (2) funciones del gestor de enganche (hook) SSDT en el módulo Registry."
}
],
"lastModified": "2026-06-16T22:49:28.353",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:core_security_technologies:core_force:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5E443EA-4C09-40DD-A018-AAA25CC011E0",
"versionEndIncluding": "0.95.167"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}