Описание
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.
Ссылки
- Vendor Advisory
- US Government Resource
- Vendor Advisory
- US Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.4 (включая)
Одно из
cpe:2.3:a:softartisans:xfile:*:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.0:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.01:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.0:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.6:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.7:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.2.4:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.29613
Средний
9.3 Critical
CVSS2
Дефекты
CWE-119
Связанные уязвимости
github
больше 4 лет назад
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.
EPSS
Процентиль: 98%
0.29613
Средний
9.3 Critical
CVSS2
Дефекты
CWE-119