7.5

CVE-2001-1022

Exploit

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnuGroff Version1.10
GnuGroff Version1.11
GnuGroff Version1.11a
GnuGroff Version1.14
GnuGroff Version1.15
GnuGroff Version1.16.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 21.22% 0.954
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P