CVE-2007-1251
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.5%
from disclosure to weapon0 days
Published on NVDMar 3
1st PoCMar 2
exploitation probability
6.5%top 7% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handling.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/3399⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://aluigi.altervista.org/adv/netrekfs-adv.txthttp://secunia.com/advisories/24357https://exchange.xforce.ibmcloud.com/vulnerabilities/32777http://sourceforge.net/project/shownotes.php?release_id=490561http://www.securityfocus.com/archive/1/461755/100/0/threadedhttp://www.securityfocus.com/bid/22786http://www.vupen.com/english/advisories/2007/0815