CVE-2008-0647
Estado: ModificadaAlta (10)—
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 7.30%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-119
Referencias
- http://secunia.com/advisories/28809
- http://www.securityfocus.com/bid/27626
- http://www.symantec.com/enterprise/security_response/weblog/2008/02/zeroday_exploit_for_lianzong_g.html
- http://www.vupen.com/english/advisories/2008/0427
- https://www.exploit-db.com/exploits/5153
- http://secunia.com/advisories/28809
- http://www.securityfocus.com/bid/27626
- http://www.symantec.com/enterprise/security_response/weblog/2008/02/zeroday_exploit_for_lianzong_g.html
- http://www.vupen.com/english/advisories/2008/0427
- https://www.exploit-db.com/exploits/5153
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-0647",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-02-07T21:00:00.000",
"references": [
{
"url": "http://secunia.com/advisories/28809",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27626",
"source": "cve@mitre.org"
},
{
"url": "http://www.symantec.com/enterprise/security_response/weblog/2008/02/zeroday_exploit_for_lianzong_g.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0427",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/5153",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28809",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27626",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/enterprise/security_response/weblog/2008/02/zeroday_exploit_for_lianzong_g.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0427",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/5153",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information."
},
{
"lang": "es",
"value": "Múltiples desbordamientos de búfer basados en pila en el ActiveX HanGamePluginCn18.HanGamePluginCn18.1 en HanGamePluginCn18.dll de Ourgame GLWorld 2.6.1.29 (también conocido como Lianzong Game Platform) permite a atacantes remotos ejecutar código de su elección a través de argumentos largos en los métodos (1) hgs_startGame y (2) hgs_startNotify, tal y como se realiza en exploits públicos desde Febrero del 2008. NOTA: alguno de estos detalles se han obtenido de información de terceros."
}
],
"lastModified": "2026-06-16T22:50:03.403",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ourgame.com:glworld:2.6.1.29:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D79D063-2064-4051-B625-880DCA7CBC3C"
},
{
"criteria": "cpe:2.3:a:ourgame.com:hangameplugincn18_activex_control:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6BC51D6-5ECB-45B2-B819-E62613A26483"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}