CVE-2005-3644
Summary
| CVE | CVE-2005-3644 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-11-17 11:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows 2000 | All | All | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp1 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp2 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp3 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | All | All |
| Operating System | Microsoft | Windows Xp | All | All | home | All |
| Operating System | Microsoft | Windows Xp | All | All | media_center | All |
| Operating System | Microsoft | Windows Xp | All | gold | professional | All |
| Operating System | Microsoft | Windows Xp | All | sp1 | home | All |
| Operating System | Microsoft | Windows Xp | All | sp1 | media_center | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | home | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | media_center | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | tablet_pc | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Your request has been blocked. This could be due to several reasons. | af854a3a-2127-422b-91ae-364da2661108 | www.microsoft.com | Vendor Advisory |
| Félicitations ! Votre domaine a bien été créé chez OVH ! | af854a3a-2127-422b-91ae-364da2661108 | www.frsirt.com | Vendor Advisory |
| Security Webinars, Podcasts, Success Stories, White Papers, and Datasheets | eEye Digital Security | af854a3a-2127-422b-91ae-364da2661108 | www.eeye.com | |
| SecurityTracker.com Archives - Microsoft Windows RPC Service May Let Remote Users Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Resources | BeyondTrust | af854a3a-2127-422b-91ae-364da2661108 | research.eeye.com | |
| Secunia - Advisories - Microsoft Windows UPnP GetDeviceList Denial of Service | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MS Windows 2k UPNP (getdevicelist) Memory Leak DoS Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Microsoft Windows Plug and Play Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecuriTeam - Windows 2000 Server UPNP DoS (Exploit) | af854a3a-2127-422b-91ae-364da2661108 | www.securiteam.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.