Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8896

Опубликовано: 04 мая 2020
Источник: nvd
CVSS3: 4.2
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 allows an attacker to perform a Man-in-the-Middle attack using a specially crafted key to read data past the end of the buffer used to hold it. Mitigation: Update to Google Earth Pro 7.3.3.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:google:earth:*:*:*:*:pro:*:*:*
Версия до 7.3.3 (исключая)

EPSS

Процентиль: 25%
0.00087
Низкий

4.2 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-119
CWE-120

Связанные уязвимости

github
больше 3 лет назад

A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 allows an attacker to perform a Man-in-the-Middle attack using a specially crafted key to read data past the end of the buffer used to hold it. Mitigation: Update to Google Earth Pro 7.3.3.

EPSS

Процентиль: 25%
0.00087
Низкий

4.2 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-119
CWE-120