Количество 4
Количество 4
CVE-2024-46993
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 28.3.2, 29.3.3, and 30.0.3, the nativeImage.createFromPath() and nativeImage.createFromBuffer() functions call a function downstream that is vulnerable to a heap buffer overflow. An Electron program that uses either of the affected functions is vulnerable to a buffer overflow if an attacker is in control of the image's height, width, and contents. This issue has been patched in versions 28.3.2, 29.3.3, and 30.0.3. There are no workarounds for this issue.
CVE-2024-46993
Electron is an open source framework for writing cross-platform deskto ...
GHSA-6r2x-8pq8-9489
Electron vulnerable to Heap Buffer Overflow in NativeImage
BDU:2025-11357
Уязвимость функций nativeImage.createFromPath() и nativeImage.createFromBuffer() фреймворка для написания приложений Electron, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-46993 Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 28.3.2, 29.3.3, and 30.0.3, the nativeImage.createFromPath() and nativeImage.createFromBuffer() functions call a function downstream that is vulnerable to a heap buffer overflow. An Electron program that uses either of the affected functions is vulnerable to a buffer overflow if an attacker is in control of the image's height, width, and contents. This issue has been patched in versions 28.3.2, 29.3.3, and 30.0.3. There are no workarounds for this issue. | 0% Низкий | 7 месяцев назад | ||
CVE-2024-46993 Electron is an open source framework for writing cross-platform deskto ... | 0% Низкий | 7 месяцев назад | ||
GHSA-6r2x-8pq8-9489 Electron vulnerable to Heap Buffer Overflow in NativeImage | 0% Низкий | 7 месяцев назад | ||
BDU:2025-11357 Уязвимость функций nativeImage.createFromPath() и nativeImage.createFromBuffer() фреймворка для написания приложений Electron, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу