{
    "id": "CVE-2004-2099",
    "published": "2004-12-31 05:00:00",
    "last_modified": "2026-06-16 22:09:00",
    "cvss_score": "5.1",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
    "cwe": null,
    "description": "Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.",
    "epss_score": "0.04281",
    "epss_percentile": "0.90812",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-03 18:17:04",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "electronic_arts",
            "product": "need_for_speed_hot_pursuit_2"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "147",
            "title": "Need for Speed 2 - Remote Client Buffer Overflow (PoC)",
            "date": "2004-01-23",
            "url": "https://www.exploit-db.com/exploits/147"
        }
    ],
    "refs_list": [
        "http://aluigi.altervista.org/adv/nfshp2cbof-adv.txt",
        "http://marc.info/?l=bugtraq&m=107479094508691&w=2",
        "http://www.securityfocus.com/bid/9473",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/14909",
        "http://aluigi.altervista.org/adv/nfshp2cbof-adv.txt",
        "http://marc.info/?l=bugtraq&m=107479094508691&w=2",
        "http://www.securityfocus.com/bid/9473",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/14909"
    ]
}