CVE detail
CVE-2006-4006 — CVE-2006-4006
Published 2006-08-07 · Modified 2026-06-16 · Vendor bomberclone · Product bomberclone · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0902
EPSS probability
exploitation probability, 30d
95.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References