CVE-2008-0912

Sybase MobiLink < 10.0.1.3629 - Remote Code Execution via Long Username, Version, or Remote ID

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0912. PoCs published by Luigi Auriemma.

AI-analyzed exploit summary The provided text describes a heap-based buffer overflow vulnerability in Sybase MobiLink 10.0.1.3629, allowing remote code execution or denial-of-service. It references ExploitDB and a GitLab link for the exploit binary but contains no actual exploit code.

Description

Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long (1) username, (2) version, or (3) remote ID. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Luigi Auriemma · textdosmultiple
https://www.exploit-db.com/exploits/31271

The provided text describes a heap-based buffer overflow vulnerability in Sybase MobiLink 10.0.1.3629, allowing remote code execution or denial-of-service. It references ExploitDB and a GitLab link for the exploit binary but contains no actual exploit code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Sybase MobiLink 10.0.1.3629
No auth needed
Prerequisites: Network access to the vulnerable Sybase MobiLink service
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/488409/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/490259/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0626
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29045
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019469
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3691
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27914

Scores

EPSS 0.1557
EPSS Percentile 96.4%

Details

CWE
CWE-119
Status published
Products (2)
sybase/mobilink < 10.0.1.3629
sybase/sql_anywhere 10.0.1.3415
Published Feb 22, 2008
Tracked Since Feb 18, 2026