CVE-2004-0608

UnknownEPSS 73.54%

Last modified

CVE-2004-0608 is a vulnerability of currently unknown severity. The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.. EPSS estimates a 73.54% chance of exploitation in the next 30 days.

Description

The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.

Metrics

EPSS Probability
73.54%

99.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
ArushDevastation390.0
DreamforgeTnn Outdoors Pro HunterAll versions
Epic GamesUnreal Engine226f
Epic GamesUnreal Engine433
Epic GamesUnreal Engine436
Epic GamesUnreal Tournament451b
Epic GamesUnreal Tournament 20032199_linux
Epic GamesUnreal Tournament 20032199_macos
Epic GamesUnreal Tournament 20032199_win32
Epic GamesUnreal Tournament 20032225_macos
Epic GamesUnreal Tournament 20032225_win32
Epic GamesUnreal Tournament 2004macos
Epic GamesUnreal Tournament 2004win32
InfogramesTacticalops3.4
InfogramesX-Com EnforcerAll versions
Ion StormDeusex1.112_fm
Nerf Arena BlastNerf Arena Blast1.2
Rage SoftwareMobile Forces20000.0
Robert JordanWheel Of Time333.0b
Running With ScissorsPostal 21337
GentooLinux1.4

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-0608?
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.
How severe is CVE-2004-0608?
Severity scoring for CVE-2004-0608 is pending analysis. The EPSS model estimates a 73.54% probability of exploitation in the next 30 days.
How do I fix CVE-2004-0608?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-0608?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST