Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-42484

Опубликовано: 01 мая 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash file. The issue affects modules 17200, 17210, 17220, 17225, and 17230. When data_type_enum<=1, attacker-controlled hex data from a user-supplied hash string is decoded into a fixed-size buffer without proper input-length validation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hashcat:hashcat:7.1.2:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00444
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787
CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash file. The issue affects modules 17200, 17210, 17220, 17225, and 17230. When data_type_enum<=1, attacker-controlled hex data from a user-supplied hash string is decoded into a fixed-size buffer without proper input-length validation.

CVSS3: 9.8
debian
4 месяца назад

A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser ...

CVSS3: 9.8
github
4 месяца назад

A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash file. The issue affects modules 17200, 17210, 17220, 17225, and 17230. When data_type_enum<=1, attacker-controlled hex data from a user-supplied hash string is decoded into a fixed-size buffer without proper input-length validation.

EPSS

Процентиль: 37%
0.00444
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787
CWE-787