Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22051

Опубликовано: 04 янв. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:github:cmark-gfm:*:*:*:*:*:*:*:*
Версия до 0.28.3.gfm.21 (исключая)
cpe:2.3:a:github:cmark-gfm:*:*:*:*:*:*:*:*
Версия от 0.29.0.gfm.0 (включая) до 0.29.0.gfm.3 (исключая)
cpe:2.3:a:gjtorikian:commonmarker:*:*:*:*:*:ruby:*:*
Версия до 0.23.4 (исключая)

EPSS

Процентиль: 91%
0.07131
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

CVSS3: 7.5
redhat
около 2 лет назад

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

CVSS3: 9.8
debian
около 2 лет назад

CommonMarker versions prior to 0.23.4 are at risk of an integer overfl ...

CVSS3: 8.8
github
почти 4 года назад

Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption

CVSS3: 9.8
fstec
около 2 лет назад

Уязвимость библиотеки CommonMarker, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 91%
0.07131
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190
CWE-190