Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10109

Опубликовано: 23 фев. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:muscle:pcsc-lite:*:*:*:*:*:*:*:*
Версия до 1.8.19 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.10:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.05
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.

CVSS3: 5.5
redhat
около 9 лет назад

Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.

CVSS3: 7.5
debian
почти 9 лет назад

Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remot ...

suse-cvrf
около 9 лет назад

Security update for pcsc-lite

suse-cvrf
около 9 лет назад

Security update for pcsc-lite

EPSS

Процентиль: 89%
0.05
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-416