Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-0127Improper Restriction of Operations within the Bounds of a Memory Buffer in E-business Server

Severity
8.8HIGHNVD
EPSS
24.6%
top 3.86%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 10
Latest updateMay 1

Description

The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet.

CVSS vector

AV:N/AC:M/C:N/I:C/A:CExploitability: 8.6 | Impact: 9.2

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vv84-p762-v8xx: The administration interface in McAfee E-Business Server 82022-05-01
CVEList
CVE-2008-0127: The administration interface in McAfee E-Business Server 82008-01-10

💥Exploits & PoCs

1
Exploit-DB
McAfee E-Business Server 8.5.2 - Remote Code Execution / Denial of Service (PoC)2008-01-09

📋Vendor Advisories

1
Red Hat
m2crypto: OpenSSL incorrect checks for malformed signatures2009-01-11
CVE-2008-0127 — Mcafee E-business Server vulnerability | cvebase