Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2f4m-q55c-v3xr

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.

EPSS

Процентиль: 27%
0.00339
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-129

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.

CVSS3: 7.5
nvd
около 1 месяца назад

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.

CVSS3: 7.5
debian
около 1 месяца назад

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel valu ...

EPSS

Процентиль: 27%
0.00339
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-129