CVE-2004-0290 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 6.1% (pctl 93)
Patch early
A public exploit exists.
Description
Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 6.15% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-11-23 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| freeform interactive | purge |
| freeform interactive | purge jihad |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Freeform Interactive Purge 1.4.7/Purge Jihad 2.0.1 Game Client - Remote Buffer Overflow | 2004-02-16 |
References
- http://marc.info/?l=bugtraq&m=107695064204362&w=2
- http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167
- http://www.securityfocus.com/bid/9671
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15216
- http://marc.info/?l=bugtraq&m=107695064204362&w=2
- http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167
- http://www.securityfocus.com/bid/9671
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15216
→ the Explorer · watch your stack · NVD