Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7374

Опубликовано: 12 авг. 2020
Источник: nvd
CVSS3: 5.3
CVSS3: 7.8
CVSS2: 6.8
EPSS Средний

Описание

Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to trigger a buffer overflow on the stack and gain remote code execution as the user running the Documalis Free PDF Editor or Documalis Free PDF Scanner software.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:documalis:free_pdf_editor:5.7.2.26:*:*:*:*:*:*:*
cpe:2.3:a:documalis:free_pdf_scanner:5.7.2.122:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.44086
Средний

5.3 Medium

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-120
CWE-120

Связанные уязвимости

github
больше 3 лет назад

Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to trigger a buffer overflow on the stack and gain remote code execution as the user running the Documalis Free PDF Editor or Documalis Free PDF Scanner software.

EPSS

Процентиль: 97%
0.44086
Средний

5.3 Medium

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-120
CWE-120