VDB
CVE-2007-3360
CVE-2007-3360
PUBLISHED
CVSS 9.300000190734863 CRITICAL
hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes shell commands.
EPSS 10.20% · 93.3th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
10.20%
93.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| bitchx | bitchx | 1.1-final |
Timeline
- Jun 22, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- SSA:2009-116-02 vendor-advisory
- 34870 third-party-advisory
- bitchx-hook-command-execution(34969) vdb
- 4087 exploit
- 24579 vdb
- 25759 third-party-advisory
- 37479 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-3360 advisory