Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-22051

Опубликовано: 04 янв. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

esm-apps/resolute

not-affected

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

lunar

not-affected

0.23.6-1build2
mantic

not-affected

Показывать по

EPSS

Процентиль: 72%
0.0145
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

CVSS3: 9.8
nvd
больше 2 лет назад

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

CVSS3: 9.8
debian
больше 2 лет назад

CommonMarker versions prior to 0.23.4 are at risk of an integer overfl ...

CVSS3: 8.8
github
больше 4 лет назад

Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость библиотеки CommonMarker, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 72%
0.0145
Низкий

9.8 Critical

CVSS3

Уязвимость CVE-2024-22051