Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-35297

Опубликовано: 01 окт. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

Scalabium dBase Viewer version 2.6 (Build 5.751) is vulnerable to remote code execution via a crafted DBF file that triggers a buffer overflow. An attacker can use the Structured Exception Handler (SEH) records and redirect execution to attacker-controlled code.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:scalabium:dbase_viewer:2.6:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01112
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-120

Связанные уязвимости

github
больше 3 лет назад

Scalabium dBase Viewer version 2.6 (Build 5.751) is vulnerable to remote code execution via a crafted DBF file that triggers a buffer overflow. An attacker can use the Structured Exception Handler (SEH) records and redirect execution to attacker-controlled code.

EPSS

Процентиль: 78%
0.01112
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-120