Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wfp-phxm-p655

Опубликовано: 28 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

NRSS RSS Reader 0.3.9-1 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -F parameter. Attackers can craft a malicious input with 256 bytes of padding followed by a controlled EIP value to overwrite the return address and achieve code execution.

NRSS RSS Reader 0.3.9-1 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -F parameter. Attackers can craft a malicious input with 256 bytes of padding followed by a controlled EIP value to overwrite the return address and achieve code execution.

EPSS

Процентиль: 10%
0.00203
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.4
ubuntu
5 месяцев назад

NRSS RSS Reader 0.3.9-1 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -F parameter. Attackers can craft a malicious input with 256 bytes of padding followed by a controlled EIP value to overwrite the return address and achieve code execution.

CVSS3: 8.4
nvd
5 месяцев назад

NRSS RSS Reader 0.3.9-1 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -F parameter. Attackers can craft a malicious input with 256 bytes of padding followed by a controlled EIP value to overwrite the return address and achieve code execution.

CVSS3: 8.4
debian
5 месяцев назад

NRSS RSS Reader 0.3.9-1 contains a stack buffer overflow vulnerability ...

EPSS

Процентиль: 10%
0.00203
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-787