Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2c9-6vfm-cc58

Опубликовано: 15 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

EPSS

Процентиль: 96%
0.21226
Средний

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость программной платформы ColdFusion, связанная с записью за границами буфера, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.21226
Средний

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787