CVE-2009-10006
Last modified
CVE-2009-10006 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. UFO: Alien Invasion versions up to and including 2.2.1 contain a buffer overflow vulnerability in its built-in IRC client component. When the client connects to an IRC server and receives a crafted numeric reply (specifically a 001 message), the application fails to properly validate the length of the response string. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
UFO: Alien Invasion versions up to and including 2.2.1 contain a buffer overflow vulnerability in its built-in IRC client component. When the client connects to an IRC server and receives a crafted numeric reply (specifically a 001 message), the application fails to properly validate the length of the response string. This results in a stack-based buffer overflow, which may corrupt control flow structures and allow arbitrary code execution. The vulnerability is triggered during automatic IRC connection handling and does not require user interaction beyond launching the game.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2009-10006?
How severe is CVE-2009-10006?
How do I fix CVE-2009-10006?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1000The Oracle Applications Framework component in Oracle E-Busi…
- CVE-2009-10001A vulnerability classified as problematic was found in jianl…6.1
- CVE-2009-10002A vulnerability, which was classified as problematic, has be…6.1
- CVE-2009-10003A vulnerability was found in capnsquarepants wordcraft up to…6.1
- CVE-2009-10004A vulnerability was found in Turante Sandbox Theme up to 1.5…6.1
- CVE-2009-10005ContentKeeper Web Appliance (now maintained by Impero Softwa…8.7
- CVE-2009-10007Catalyst::Plugin::Authentication versions before 0.10_027 fo…9.1
- CVE-2009-1001Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 …
- CVE-2009-1002Unspecified vulnerability in Oracle BEA WebLogic Server 10.3…
- CVE-2009-1003Unspecified vulnerability in the WebLogic Server component i…
- CVE-2009-1004Unspecified vulnerability in the WebLogic Server component i…
- CVE-2009-1005Unspecified vulnerability in the Oracle Data Service Integra…
Are you affected by CVE-2009-10006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
