peter bassill · operator
$ cve CVE-2008-3116 JSON

CVE-2008-3116 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 5.6% (pctl 93)

Patch early

A public exploit exists.

Description

Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows remote attackers to execute arbitrary code via format string specifiers in a chat message.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS5.55% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploityes
Published2008-07-10
Last modified2026-06-16

Affected (3)

VendorProduct
hanghai5th street
hanghaihigh street 5
hanghaihot step

Public exploits

SourceTitleDate
exploit-db5th street - 'dx8render.dll' Format String2008-06-25

References

→ the Explorer  ·  watch your stack  ·  NVD