Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5089

Опубликовано: 05 нояб. 2019
Источник: nvd
CVSS3: 8.8
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially crafted JPEG file can cause an out-of-bounds memory write, allowing an attacker to execute arbitrary code on the victim machine. An attacker could exploit a vulnerability by providing the user with a specially crafted JPEG file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:investintech:able2extract:14.0.7:*:*:*:professional:*:x64:*

EPSS

Процентиль: 56%
0.00335
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially crafted JPEG file can cause an out-of-bounds memory write, allowing an attacker to execute arbitrary code on the victim machine. An attacker could exploit a vulnerability by providing the user with a specially crafted JPEG file.

EPSS

Процентиль: 56%
0.00335
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-190
CWE-190