Back to CVE List

CVE-2018-25223

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-787
Source
NVD
Vendor
crashmail
Product
Crashmail

External References

Discussion (0)

Add Comment

No comments yet. Be the first!