Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gm3h-4v52-g4fr

Опубликовано: 08 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.

The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 6.8
nvd
около 3 лет назад

The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

Дефекты

CWE-120