Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-12194

Опубликовано: 14 мар. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:spice-gtk_project:spice-gtk:*:*:*:*:*:*:*:*
Версия до 0.34 (включая)

EPSS

Процентиль: 81%
0.01485
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-121
CWE-20

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

CVSS3: 5.5
redhat
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

CVSS3: 9.8
debian
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages se ...

suse-cvrf
почти 8 лет назад

Security update for spice-gtk

suse-cvrf
почти 8 лет назад

Security update for spice-gtk

EPSS

Процентиль: 81%
0.01485
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-121
CWE-20