Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-20111

Опубликовано: 18 нояб. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunction with CVE-2015-6031 exploitation.

EPSS

Процентиль: 83%
0.01938
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
debian
около 1 года назад

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other ...

CVSS3: 9.8
github
около 1 года назад

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunction with CVE-2015-6031 exploitation.

EPSS

Процентиль: 83%
0.01938
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120