CVE-2018-25223
CRITICAL SEVERITYCVSS Score & Metrics
Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-787
Source
NVD
Vendor
crashmail
Product
Crashmail
Discussion (0)
Add Comment
No comments yet. Be the first!