← Späť na vyhľadávanie CVE

CVE-2018-25223

Crashmail

Popis

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

CVSS 9.8EPSS 0.8840000000000001%Riziko 1.06
Zobraziť zdroj
Zverejnené
2026-03-28 12:16:03
Dotknuté verzie
==1.6
Typ
Package
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H