CVE-2008-3338

Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkhma), as used in TIBCO Hawk before 4.8.1; Runtime Agent (TRA) before 5.6.0; iProcess Engine 10.3.0 through 10.6.2 and 11.0.0; and Mainframe Service Tracker before 1.1.0 might allow remote attackers to execute arbitrary code via a crafted message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
tibcohawk
𝑥
≤ 4.8.0
tibcohawk
4.6.0
tibcohawk
4.6.1
tibcohawk
4.7
tibcoiprocess_engine
10.3.0
tibcoiprocess_engine
10.3.1
tibcoiprocess_engine
10.3.2
tibcoiprocess_engine
10.3.3
tibcoiprocess_engine
10.3.4
tibcoiprocess_engine
10.3.5
tibcoiprocess_engine
10.4
tibcoiprocess_engine
10.4.1
tibcoiprocess_engine
10.5
tibcoiprocess_engine
10.6
tibcoiprocess_engine
10.6.0
tibcoiprocess_engine
10.6.1
tibcoiprocess_engine
10.6.2
tibcoiprocess_engine
11.0
tibcomainframe_service_tracker
𝑥
≤ 1.0
tibcoruntime_agent
𝑥
≤ 5.5.4
tibcoruntime_agent
5.3
tibcoruntime_agent
5.4.0
𝑥
= Vulnerable software versions