Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-1000172

Опубликовано: 17 нояб. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sublexer' pointer has been freed. Line 542 of gravity_lexer.c. 'lexer' is being used to access a variable but 'lexer' has already been freed, creating a Heap Use-After-Free condition.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:creolabs:gravity:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01132
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sublexer' pointer has been freed. Line 542 of gravity_lexer.c. 'lexer' is being used to access a variable but 'lexer' has already been freed, creating a Heap Use-After-Free condition.

EPSS

Процентиль: 78%
0.01132
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-416