Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-982x-c5f9-g2p4

Опубликовано: 08 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.4

Описание

Photodex ProShow Producer version 5.0.3256 contains a stack-based buffer overflow vulnerability in the handling of plugin load list files. When a specially crafted load file is placed in the installation directory, the application fails to properly validate its contents, leading to a buffer overflow when the file is parsed during startup. Exploitation requires local access to place the file and user interaction to launch the application.

Photodex ProShow Producer version 5.0.3256 contains a stack-based buffer overflow vulnerability in the handling of plugin load list files. When a specially crafted load file is placed in the installation directory, the application fails to properly validate its contents, leading to a buffer overflow when the file is parsed during startup. Exploitation requires local access to place the file and user interaction to launch the application.

EPSS

Процентиль: 91%
0.06899
Низкий

8.4 High

CVSS4

Дефекты

CWE-121

Связанные уязвимости

nvd
6 месяцев назад

Photodex ProShow Producer version 5.0.3256 contains a stack-based buffer overflow vulnerability in the handling of plugin load list files. When a specially crafted load file is placed in the installation directory, the application fails to properly validate its contents, leading to a buffer overflow when the file is parsed during startup. Exploitation requires local access to place the file and user interaction to launch the application.

EPSS

Процентиль: 91%
0.06899
Низкий

8.4 High

CVSS4

Дефекты

CWE-121