CVE-2008-3680

The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
flagship_industriesventrilo
1.01
flagship_industriesventrilo
1.03
flagship_industriesventrilo
1.04
flagship_industriesventrilo
1.05
flagship_industriesventrilo
1.06
flagship_industriesventrilo
2.1
flagship_industriesventrilo
2.1.1
flagship_industriesventrilo
2.1.2
flagship_industriesventrilo
2.1.3
flagship_industriesventrilo
2.1.4
flagship_industriesventrilo
2.2
flagship_industriesventrilo
2.3
flagship_industriesventrilo
2.3.2:prototype.6
flagship_industriesventrilo
2.3.2:prototype.9
flagship_industriesventrilo
3.0.2
𝑥
= Vulnerable software versions