PoC Index

CVE-2004-2592

MEDIUM 5.0EPSS 3.7%

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at a negative array offset, which is not handled when processing Configstrings and Baselines.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
3.72% chance of exploitation in the next 30 days, 89th percentile
Published
2005-11-29
Updated
2024-08-08

ExploitDB entries (1)

References

Related