Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj2v-35pf-65rw

Опубликовано: 26 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.4

Описание

A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system.

A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system.

EPSS

Процентиль: 1%
0.00103
Низкий

4.4 Medium

CVSS4

Дефекты

CWE-122

Связанные уязвимости

nvd
2 месяца назад

A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system.

EPSS

Процентиль: 1%
0.00103
Низкий

4.4 Medium

CVSS4

Дефекты

CWE-122