Description
Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a command.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Luigi Auriemma · textremotemultiple
https://www.exploit-db.com/exploits/25190
References (4)
Core 4
Core References
Exploit, Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/14483
Exploit, Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/12727
Vendor Advisory vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1013361
Vendor Advisory x_refsource_misc
http://aluigi.altervista.org/adv/ca3dex-adv.txt
Scores
EPSS
0.1545
EPSS Percentile
94.7%
Details
Status
published
Products (1)
ca3de/ca3de
< march_2004
Published
Mar 03, 2005
Tracked Since
Feb 18, 2026