CVE-2019-25626
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.4 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbitrary code by supplying a malicious activation code string. Attackers can craft a buffer containing 608 bytes of junk data followed by shellcode and SEH chain overwrite values to trigger code execution when the activation dialog processes the input.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-434
Source
NVD
Vendor
Flexhex
Product
River Past Cam Do
Discussion (0)
Add Comment
No comments yet. Be the first!