Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-8728

Опубликовано: 24 апр. 2018
Источник: nvd
CVSS3: 8.6
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:artifex:mupdf:1.10:rc1:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00586
Низкий

8.6 High

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.

CVSS3: 7.8
debian
почти 8 лет назад

An exploitable heap out of bounds write vulnerability exists in the Fi ...

CVSS3: 7.8
github
больше 3 лет назад

An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.

suse-cvrf
около 8 лет назад

Security update for mupdf

EPSS

Процентиль: 69%
0.00586
Низкий

8.6 High

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-787