← Vulnerability feed

Vulnerability record · CVE-2006-0460 · published 17 February 2006

CVE-2006-0460: BomberClone buffer overflows via long error messages

BBomberclone · Bomberclone

BomberClone before 0.11.6.2 contains multiple buffer overflows triggered by long error messages. A remote attacker can send crafted messages that overflow buffers and potentially execute arbitrary code. The flaw is network-reachable and requires no authentication, making it a serious risk for exposed game servers.

7.5 CVSS 2.0 High EPSS 68% · top 0.7%
7.5CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with a high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.

What it is

BomberClone before 0.11.6.2 contains multiple buffer overflows triggered by long error messages. A remote attacker can send crafted messages that overflow buffers and potentially execute arbitrary code. The flaw is network-reachable and requires no authentication, making it a serious risk for exposed game servers.

Impact

An attacker can execute arbitrary code with the privileges of the BomberClone process, or at minimum crash it. This gives full compromise of the affected host or service.

Attack surface

Reachable over the network via the game's message handling, as indicated by the AV:N vector. No authentication or user interaction is required per the CVSS vector (Au:N) and the description of remote attackers.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, though EPSS is high at 0.68 (99th percentile), suggesting elevated likelihood of exploitation activity.

What to do

  • Upgrade BomberClone to 0.11.6.2 or later, applying the vendor patch referenced in the Gentoo advisory.
  • Apply the Debian DSA-997 update if running the Debian package.
  • Restrict network access to BomberClone servers to trusted clients only.
  • Monitor for and block malformed or oversized error messages at the network boundary.
  • Retire or isolate unsupported BomberClone deployments that cannot be patched.

Detection

  • Inspect network traffic for oversized or malformed BomberClone error messages.
  • Monitor BomberClone process crashes or abnormal terminations for signs of overflow attempts.
  • Watch for unexpected child processes or shell activity spawned by the BomberClone service.
  • Review host logs for memory corruption indicators tied to the game process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-0460 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-0460), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.