Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vqp7-jhj6-766w

Опубликовано: 22 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code.

A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code.

EPSS

Процентиль: 61%
0.00418
Низкий

7.8 High

CVSS3

Дефекты

CWE-755

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code.

EPSS

Процентиль: 61%
0.00418
Низкий

7.8 High

CVSS3

Дефекты

CWE-755