Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c6v-5c62-gv3h

Опубликовано: 13 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

AUTOMGEN versions up to and including 8.0.0.7 (also referenced as 8.022) contain a vulnerability in that project file handling frees an object and subsequently dereferences the stale pointer when processing certain malformed fields. The dangling-pointer use enables an attacker to influence an indirect call through attacker-controlled memory, resulting in denial-of-service. In some conditions, remote code execution may be possible.

AUTOMGEN versions up to and including 8.0.0.7 (also referenced as 8.022) contain a vulnerability in that project file handling frees an object and subsequently dereferences the stale pointer when processing certain malformed fields. The dangling-pointer use enables an attacker to influence an indirect call through attacker-controlled memory, resulting in denial-of-service. In some conditions, remote code execution may be possible.

EPSS

Процентиль: 70%
0.00642
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-416

Связанные уязвимости

nvd
около 1 месяца назад

AUTOMGEN versions up to and including 8.0.0.7 (also referenced as 8.022) contain a vulnerability in that project file handling frees an object and subsequently dereferences the stale pointer when processing certain malformed fields. The dangling-pointer use enables an attacker to influence an indirect call through attacker-controlled memory, resulting in denial-of-service. In some conditions, remote code execution may be possible.

msrc
около 1 месяца назад

IRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS

EPSS

Процентиль: 70%
0.00642
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-416