Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-37576

Опубликовано: 08 янв. 2024
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the vcd2vzt conversion utility.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tonybybell:gtkwave:3.3.115:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00131
Низкий

7.8 High

CVSS3

Дефекты

CWE-416
CWE-416

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the vcd2vzt conversion utility.

CVSS3: 7.8
debian
больше 1 года назад

Multiple use-after-free vulnerabilities exist in the VCD get_vartoken ...

CVSS3: 7.8
github
больше 1 года назад

Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the vcd2vzt conversion utility.

EPSS

Процентиль: 33%
0.00131
Низкий

7.8 High

CVSS3

Дефекты

CWE-416
CWE-416