Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-62gh-7323-4v89

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Adobe svg-native-viewer 8182d14dfad5d1e10f53ed830328d7d9a3cfa96d and earlier versions are affected by a heap buffer overflow vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

Adobe svg-native-viewer 8182d14dfad5d1e10f53ed830328d7d9a3cfa96d and earlier versions are affected by a heap buffer overflow vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

EPSS

Процентиль: 95%
0.18651
Средний

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

Adobe svg-native-viewer 8182d14dfad5d1e10f53ed830328d7d9a3cfa96d and earlier versions are affected by a heap buffer overflow vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость библиотеки Adobe SVG Native viewer, связанная с переполнением буфера в куче, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 95%
0.18651
Средний

Дефекты

CWE-122