Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ollydbg | ollydbg | 1.0.8b |
| ollydbg | ollydbg | 1.10 |
| ollydbg | ollydbg | 1.0.9 |
| ollydbg | ollydbg | 1.0.6 |
OllyDbg 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a dynamic link library (DLL) with a long filename.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ollydbg | ollydbg | 1.10 |
| ollydbg | ollydbg | 1.09 |
| ollydbg | ollydbg | 1.06 |
| ollydbg | ollydbg | 1.08b |
Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary code via a crafted DLL file that contains a long string.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mackt | imprec | 1.7 |
| ollydbg | ollydbg | 1.10 |