CVE-2006-1194
ENet < Jul 2005 - DoS
Title source: llmDescription
Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet with a large command length value, which leads to an invalid memory access.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Luigi Auriemma · cdosmultiple
https://www.exploit-db.com/exploits/27420
References (9)
Scores
EPSS
0.1595
EPSS Percentile
94.8%
Details
Status
published
Products (1)
enet/enet_library
< jul_2005
Published
Mar 13, 2006
Tracked Since
Feb 18, 2026