Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3404

Опубликовано: 04 мар. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ytnef_project:ytnef:1.9.3:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.02066
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-119
CWE-787

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

CVSS3: 7.8
debian
почти 5 лет назад

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote att ...

CVSS3: 7.8
github
больше 3 лет назад

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

EPSS

Процентиль: 83%
0.02066
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-119
CWE-787