RSS   Vulnerabilities for 'Wesnoth'   RSS

2009-03-12
 
CVE-2009-0878

CWE-399
 

 
The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a map with a large (1) width or (2) height.

 
2009-03-04
 
CVE-2009-0367

CWE-264
 

 
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.

 
2009-03-12
 
CVE-2009-0366

CWE-399
 

 
The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service via a large compressed WML document.

 
2007-12-01
 
CVE-2007-6201

CWE-noinfo
 

 
Unspecified vulnerability in Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows attackers to cause a denial of service (hang) via a "faulty add-on" and possibly execute other commands via unknown vectors related to the turn_cmd option.

 
 
CVE-2007-5742

CWE-22
 

 
Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote attackers to read arbitrary files via ".." sequences in unknown vectors.

 
2007-10-11
 
CVE-2007-3917

CWE-134
 

 
The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters that can produce an invalid UTF-8 string after it is truncated, which triggers an uncaught exception, involving the truncate_message function in server/server.cpp. NOTE: this issue affects both clients and servers.

 

 >>> Vendor: Wesnoth 2 Products
Wesnoth
Battle for wesnoth


Copyright 2024, cxsecurity.com

 

Back to Top