Description
Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stack‑based buffer overflow in the OP_SERVERMESSAGE handler of aMule 2.3.3. A remote attacker can send a specially crafted message that overflows a buffer on the server side, causing the aMule process to crash and leading to a denial of service. The flaw is identified as CWE-121 and carries a CVSS score of 7.5, indicating moderate to high severity.

Affected Systems

aMule – the peer‑to‑peer file sharing application – version 2.3.3 is affected. No other vendor or product versions are listed in the CNA data.

Risk and Exploitability

The EPSS score of less than 1% suggests exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. However, because the flaw can be triggered remotely by an attacker who can send a malicious OP_SERVERMESSAGE, the risk remains for systems exposed to untrusted peers. An attacker would need to send a crafted message to the aMule server; no additional compromises are required. The impact is a crash of the aMule service, causing a service interruption in the network using it.

Generated by OpenCVE AI on July 31, 2026 at 10:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade aMule to a version that contains the buffer overflow fix, such as version 2.3.4 or later.
  • If an upgrade cannot be performed immediately, place the aMule service behind a firewall that only allows inbound connections from trusted network hosts or block the OP_SERVERMESSAGE handler at the network level to reduce exposure.
  • Monitor system logs for segmentation faults or repeated crashes and apply runtime memory protection measures or input validation if possible.

Generated by OpenCVE AI on July 31, 2026 at 10:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Stack‑Based Buffer Overflow in aMule's OP_SERVERMESSAGE Causes Remote Denial of Service

Sat, 25 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in aMule 2.3.3 Causes Denial of Service

Thu, 23 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in aMule 2.3.3 Causes Denial of Service

Mon, 20 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in OP_SERVERMESSAGE Handler of aMule 2.3.3 Leading to Denial of Service

Thu, 16 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in OP_SERVERMESSAGE Handler of aMule 2.3.3 Leading to Denial of Service

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-14T15:21:29.814Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51105

cve-icon Vulnrichment

Updated: 2026-07-14T15:21:25.534Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:00:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow