CVE-2008-3116 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 5.6% (pctl 93)
Patch early
A public exploit exists.
Description
Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows remote attackers to execute arbitrary code via format string specifiers in a chat message.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 5.55% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-134 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-07-10 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| hanghai | 5th street |
| hanghai | high street 5 |
| hanghai | hot step |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | 5th street - 'dx8render.dll' Format String | 2008-06-25 |
References
- http://securityreason.com/securityalert/3982
- http://www.securityfocus.com/archive/1/493649/100/0/threaded
- http://www.securityfocus.com/bid/29928
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43370
- http://securityreason.com/securityalert/3982
- http://www.securityfocus.com/archive/1/493649/100/0/threaded
- http://www.securityfocus.com/bid/29928
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43370
→ the Explorer · watch your stack · NVD