Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmwg-vmx2-qg37

Опубликовано: 28 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 77%
0.01055
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.5
nvd
около 1 года назад

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 77%
0.01055
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-94