Описание
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.
Ссылки
- Vendor Advisory
- US Government Resource
- Vendor Advisory
- US Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.4 (включая)
Одно из
cpe:2.3:a:softartisans:xfile:*:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.0:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.01:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.0:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.6:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.1.7:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:softartisans:xfile:2.2.4:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.65758
Средний
9.3 Critical
CVSS2
Дефекты
CWE-119
Связанные уязвимости
github
почти 4 года назад
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.
EPSS
Процентиль: 98%
0.65758
Средний
9.3 Critical
CVSS2
Дефекты
CWE-119