Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11858

Опубликовано: 15 дек. 2024
Источник: nvd
CVSS3: 8.6
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*
Версия до 5.9.8 (включая)

EPSS

Процентиль: 11%
0.00039
Низкий

8.6 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 года назад

A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​

CVSS3: 8.6
debian
около 1 года назад

A flaw was found in Radare2, which contains a command injection vulner ...

CVSS3: 8.6
github
около 1 года назад

A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​

EPSS

Процентиль: 11%
0.00039
Низкий

8.6 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-78