Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6r2p-g46p-77hr

Опубликовано: 06 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

EPSS

Процентиль: 28%
0.00098
Низкий

7.8 High

CVSS3

Дефекты

CWE-190
CWE-680

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

EPSS

Процентиль: 28%
0.00098
Низкий

7.8 High

CVSS3

Дефекты

CWE-190
CWE-680