RSS   Vulnerabilities for 'Core force'   RSS

2008-01-18
 
CVE-2008-0366

CWE-119
 

 
CORE FORCE before 0.95.172 does not properly validate arguments to SSDT hook handler functions in the Registry module, which allows local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments.

 
 
CVE-2008-0365

CWE-119
 

 
Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.

 


Copyright 2024, cxsecurity.com

 

Back to Top