Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3r68-64pc-x636

Опубликовано: 06 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

EPSS

Процентиль: 38%
0.00166
Низкий

7.8 High

CVSS3

Дефекты

CWE-190
CWE-680

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

EPSS

Процентиль: 38%
0.00166
Низкий

7.8 High

CVSS3

Дефекты

CWE-190
CWE-680