VDB
CVE-2007-4443
CVE-2007-4443
PUBLISHED
CVSS 5 MEDIUM
The UCC dedicated server for the Unreal engine, possibly 2003 and 2004, on Windows allows remote attackers to cause a denial of service (continuous beep and server slowdown) via a string containing many 0x07 characters in (1) a request to the images/ directory, (2) the Content-Type field, (3) a HEAD request, and possibly other unspecified vectors.
EPSS 1.29% · 80.0th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.29%
80.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| epic_games | unreal_engine | 2003, 2004 |
| n/a | n/a | n/a |
Timeline
- Aug 21, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 20070818 Unexploitable buffer-overflow in the logging function of the Unreal engine mailing-list
- 26506 third-party-advisory
- 3039 third-party-advisory
- unreal-multiple-command-dos(36103) vdb
- 20070829 Re: Unexploitable buffer-overflow in the logging function of the Unreal engine mailing-list
- 20070829 Re[2]: Unexploitable buffer-overflow in the logging function of the Unreal engine mailing-list
- http://aluigi.org/poc/unrwebdos.zip url
- http://aluigi.org/adv/unrwebdos-adv.txt url
- https://nvd.nist.gov/vuln/detail/CVE-2007-4443 advisory