Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr97-553h-m39w

Опубликовано: 12 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function.

SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function.

EPSS

Процентиль: 41%
0.00191
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 9.8
nvd
11 месяцев назад

SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is not in the VPN software, but is instead in a separate tool that has no untrusted input and runs under the user's own privileges (it is a stress-testing tool for a networking stack).

EPSS

Процентиль: 41%
0.00191
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416