Логотип exploitDog
bind:CVE-2024-11477
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-11477

Количество 6

Количество 6

ubuntu логотип

CVE-2024-11477

около 1 года назад

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.

CVSS3: 7.8
EPSS: Средний
nvd логотип

CVE-2024-11477

около 1 года назад

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.

CVSS3: 7.8
EPSS: Средний
debian логотип

CVE-2024-11477

около 1 года назад

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution ...

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-882h-ff2x-f86q

около 1 года назад

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.

CVSS3: 7.8
EPSS: Средний
fstec логотип

BDU:2024-10036

около 1 года назад

Уязвимость реализации метода сжатия Zstandard архиватора 7-Zip, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
EPSS: Средний
redos логотип

ROS-20250114-12

около 1 года назад

Уязвимость 7zip

CVSS3: 7.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-11477

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.

CVSS3: 7.8
40%
Средний
около 1 года назад
nvd логотип
CVE-2024-11477

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.

CVSS3: 7.8
40%
Средний
около 1 года назад
debian логотип
CVE-2024-11477

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution ...

CVSS3: 7.8
40%
Средний
около 1 года назад
github логотип
GHSA-882h-ff2x-f86q

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.

CVSS3: 7.8
40%
Средний
около 1 года назад
fstec логотип
BDU:2024-10036

Уязвимость реализации метода сжатия Zstandard архиватора 7-Zip, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
40%
Средний
около 1 года назад
redos логотип
ROS-20250114-12

Уязвимость 7zip

CVSS3: 7.8
40%
Средний
около 1 года назад

Уязвимостей на страницу