CVE-2004-0238 describes multiple buffer overflow vulnerabilities in Overkill (0verkill) 0.15pre3. These flaws could allow local users to execute arbitrary code in the client via a long HOME environment variable, and potentially remote attackers to execute arbitrary code through long strings in the send_message function or the server's parse_command_line function. With a CVSS score of 7.2, this vulnerability is considered high severity, indicating a local attack vector with low complexity and complete compromise of confidentiality, integrity, and availability. Its EPSS score is low, suggesting a minimal likelihood of exploitation in the wild. There is no evidence of active exploitation, nor is it listed in CISA's KEV catalog. While an ExploitDB entry exists for a similar version (0.16), there are no Metasploit or Nuclei modules, and community discussion and media coverage are virtually nonexistent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.16CPE matchmatch criteria | cpe:2.3:a:0verkill:0verkill:0.16:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.