Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16530

Опубликовано: 09 апр. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process creating a denial-of-service. While no known Remote Code Execution (RCE) vulnerabilities exist, as with all buffer overflows, the possibility of RCE cannot be completely ruled out. Data Execution Protection (DEP) is already enabled on the Email appliance as a risk mitigation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:forcepoint:email_security:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:forcepoint:email_security:8.5.3:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.04975
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process creating a denial-of-service. While no known Remote Code Execution (RCE) vulnerabilities exist, as with all buffer overflows, the possibility of RCE cannot be completely ruled out. Data Execution Protection (DEP) is already enabled on the Email appliance as a risk mitigation.

EPSS

Процентиль: 89%
0.04975
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-787