CVE-2004-0608
Last modified
CVE-2004-0608 is a vulnerability of currently unknown severity. The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.. EPSS estimates a 73.54% chance of exploitation in the next 30 days.
Description
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arush | Devastation | 390.0 |
| Dreamforge | Tnn Outdoors Pro Hunter | All versions |
| Epic Games | Unreal Engine | 226f |
| Epic Games | Unreal Engine | 433 |
| Epic Games | Unreal Engine | 436 |
| Epic Games | Unreal Tournament | 451b |
| Epic Games | Unreal Tournament 2003 | 2199_linux |
| Epic Games | Unreal Tournament 2003 | 2199_macos |
| Epic Games | Unreal Tournament 2003 | 2199_win32 |
| Epic Games | Unreal Tournament 2003 | 2225_macos |
| Epic Games | Unreal Tournament 2003 | 2225_win32 |
| Epic Games | Unreal Tournament 2004 | macos |
| Epic Games | Unreal Tournament 2004 | win32 |
| Infogrames | Tacticalops | 3.4 |
| Infogrames | X-Com Enforcer | All versions |
| Ion Storm | Deusex | 1.112_fm |
| Nerf Arena Blast | Nerf Arena Blast | 1.2 |
| Rage Software | Mobile Forces | 20000.0 |
| Robert Jordan | Wheel Of Time | 333.0b |
| Running With Scissors | Postal 2 | 1337 |
| Gentoo | Linux | 1.4 |
References
- http://aluigi.altervista.org/adv/unsecure-adv.txtVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200407-14.xmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/10570Exploit, Vendor Advisory
- http://aluigi.altervista.org/adv/unsecure-adv.txtVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200407-14.xmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/10570Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0608?
How severe is CVE-2004-0608?
How do I fix CVE-2004-0608?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0602The binary compatibility mode for FreeBSD 4.x and 5.x does n…
- CVE-2004-0603gzexe in gzip 1.3.3 and earlier will execute an argument whe…
- CVE-2004-0604The HTTP client and server in giFT-FastTrack 0.8.6 and earli…
- CVE-2004-0605Non-registered IRC users using (1) ircd-hybrid 7.0.1 and ear…
- CVE-2004-0606Cross-site scripting (XSS) vulnerability in Infoblox DNS One…
- CVE-2004-0607The eay_check_x509cert function in KAME Racoon successfully …
- CVE-2004-0609rssh 2.0 through 2.1.x expands command line arguments before…
- CVE-2004-0610The Web administration interface in Microsoft MN-500 Wireles…
- CVE-2004-0611Web-Based Administration in Netgear FVS318 VPN Router allows…
- CVE-2004-0612The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not…
- CVE-2004-0613osTicket allows remote attackers to view sensitive uploaded …
- CVE-2004-0614osTicket trusts a hidden form field in the submit form to li…
Are you affected by CVE-2004-0608?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
