Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqgj-pcrq-fwjh

Опубликовано: 28 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized argument to the -p parameter. Attackers can invoke yasr with a crafted payload containing junk data, shellcode, and a return address to overwrite the stack and trigger code execution.

Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized argument to the -p parameter. Attackers can invoke yasr with a crafted payload containing junk data, shellcode, and a return address to overwrite the stack and trigger code execution.

EPSS

Процентиль: 6%
0.00163
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.4
ubuntu
5 месяцев назад

Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized argument to the -p parameter. Attackers can invoke yasr with a crafted payload containing junk data, shellcode, and a return address to overwrite the stack and trigger code execution.

CVSS3: 8.4
nvd
5 месяцев назад

Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized argument to the -p parameter. Attackers can invoke yasr with a crafted payload containing junk data, shellcode, and a return address to overwrite the stack and trigger code execution.

CVSS3: 8.4
debian
5 месяцев назад

Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows loca ...

EPSS

Процентиль: 6%
0.00163
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-22