{"api_version":"1","generated_at":"2026-07-23T14:20:58+00:00","cve":"CVE-2008-0365","urls":{"html":"https://cve.report/CVE-2008-0365","api":"https://cve.report/api/cve/CVE-2008-0365.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0365","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0365"},"summary":{"title":"CVE-2008-0365","description":"Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-01-18 23:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/27341","name":"http://www.securityfocus.com/bid/27341","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CORE FORCE Firewall and Registry Modules Multiple Local Kernel Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/486513/100/0/threaded","name":"http://www.securityfocus.com/archive/1/486513/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0242","name":"http://www.vupen.com/english/advisories/2008/0242","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.coresecurity.com/?action=item&id=2025","name":"http://www.coresecurity.com/?action=item&id=2025","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Core Security | Cyber Threat Prevention & Identity Governance","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://securityreason.com/securityalert/3555","name":"http://securityreason.com/securityalert/3555","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CORE FORCE Kernel Buffer Overflow - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1019245","name":"http://www.securitytracker.com/id?1019245","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - CORE FORCE Buffer Overflows and Input Validation Flaws Let Local Users Gain Elevated Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://force.coresecurity.com/index.php?module=articles&func=display&aid=32","name":"http://force.coresecurity.com/index.php?module=articles&func=display&aid=32","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CORE FORCE - CORE FORCE R0.95 updated to address security vulnerabilities","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39758","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39758","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0365","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0365","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"365","vulnerable":"1","versionEndIncluding":"0.95.167","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"core_security_technologies","cpe5":"core_force","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:39:35.183Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://force.coresecurity.com/index.php?module=articles&func=display&aid=32"},{"name":"27341","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27341"},{"name":"coreforce-firewall-registry-bo(39758)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39758"},{"name":"20080117 CORE-2007-1119: CORE FORCE Kernel Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/486513/100/0/threaded"},{"name":"ADV-2008-0242","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0242"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.coresecurity.com/?action=item&id=2025"},{"name":"3555","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3555"},{"name":"1019245","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019245"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://force.coresecurity.com/index.php?module=articles&func=display&aid=32"},{"name":"27341","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27341"},{"name":"coreforce-firewall-registry-bo(39758)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39758"},{"name":"20080117 CORE-2007-1119: CORE FORCE Kernel Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/486513/100/0/threaded"},{"name":"ADV-2008-0242","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0242"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.coresecurity.com/?action=item&id=2025"},{"name":"3555","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3555"},{"name":"1019245","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019245"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0365","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://force.coresecurity.com/index.php?module=articles&func=display&aid=32","refsource":"CONFIRM","url":"http://force.coresecurity.com/index.php?module=articles&func=display&aid=32"},{"name":"27341","refsource":"BID","url":"http://www.securityfocus.com/bid/27341"},{"name":"coreforce-firewall-registry-bo(39758)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39758"},{"name":"20080117 CORE-2007-1119: CORE FORCE Kernel Buffer Overflow","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/486513/100/0/threaded"},{"name":"ADV-2008-0242","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0242"},{"name":"http://www.coresecurity.com/?action=item&id=2025","refsource":"CONFIRM","url":"http://www.coresecurity.com/?action=item&id=2025"},{"name":"3555","refsource":"SREASON","url":"http://securityreason.com/securityalert/3555"},{"name":"1019245","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019245"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0365","datePublished":"2008-01-18T22:00:00.000Z","dateReserved":"2008-01-18T00:00:00.000Z","dateUpdated":"2024-08-07T07:39:35.183Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-01-18 23:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:core_security_technologies:core_force:*:*:*:*:*:*:*:*","versionEndIncluding":"0.95.167","matchCriteriaId":"C5E443EA-4C09-40DD-A018-AAA25CC011E0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"365","Ordinal":"1","Title":"CVE-2008-0365","CVE":"CVE-2008-0365","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"365","Ordinal":"1","NoteData":"Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.","Type":"Description","Title":"CVE-2008-0365"},{"CveYear":"2008","CveId":"365","Ordinal":"2","NoteData":"2008-01-18","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"365","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}