CVE-2006-6183
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 71%
from disclosure to weapon0 days
Published on NVDDec 1
1st PoCNov 27
metasploitNov 27
exploitation probability
71%top 1% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long mode field (aka transporting mode) in a (1) GET or (2) PUT command.
Affected products
n/a · n/apublic PoCs found — 5
exploitdbwww.exploit-db.com/exploits/2855unverifiedexploitdbwww.exploit-db.com/exploits/16347unverifiedexploitdbwww.exploit-db.com/exploits/2865unverifiedexploitdbwww.exploit-db.com/exploits/3388unverifiedexploitdbwww.exploit-db.com/exploits/3170unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/23113http://securityreason.com/securityalert/1930https://exchange.xforce.ibmcloud.com/vulnerabilities/30545http://www.securityfocus.com/archive/1/452754/100/0/threadedhttp://www.securityfocus.com/bid/21301http://www.securityfocus.com/bid/21322http://www.vupen.com/english/advisories/2006/4738