Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp97-993h-745q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write via an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process.

Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write via an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process.

EPSS

Процентиль: 61%
0.00407
Низкий

Дефекты

CWE-824

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write via an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process.

EPSS

Процентиль: 61%
0.00407
Низкий

Дефекты

CWE-824