Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7v3h-hrvp-35cg

Опубликовано: 26 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields settings dialog processes the malicious input in the Label field.

PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields settings dialog processes the malicious input in the Label field.

EPSS

Процентиль: 4%
0.00016
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.4
nvd
20 дней назад

PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields settings dialog processes the malicious input in the Label field.

EPSS

Процентиль: 4%
0.00016
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-787