6.8

CVE-2008-0553

Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tcl TkTcl Tk Version <= 8.4.17
Tcl TkTcl Tk Version2.1
Tcl TkTcl Tk Version3.3
Tcl TkTcl Tk Version4.0p1
Tcl TkTcl Tk Version6.1
Tcl TkTcl Tk Version6.1p1
Tcl TkTcl Tk Version6.2
Tcl TkTcl Tk Version6.4
Tcl TkTcl Tk Version6.5
Tcl TkTcl Tk Version6.6
Tcl TkTcl Tk Version6.7
Tcl TkTcl Tk Version7.0
Tcl TkTcl Tk Version7.1
Tcl TkTcl Tk Version7.3
Tcl TkTcl Tk Version7.4
Tcl TkTcl Tk Version7.5
Tcl TkTcl Tk Version7.5p1
Tcl TkTcl Tk Version7.6
Tcl TkTcl Tk Version7.6p2
Tcl TkTcl Tk Version8.0
Tcl TkTcl Tk Version8.0.3
Tcl TkTcl Tk Version8.0.4
Tcl TkTcl Tk Version8.0.5
Tcl TkTcl Tk Version8.0p2
Tcl TkTcl Tk Version8.1
Tcl TkTcl Tk Version8.1.1
Tcl TkTcl Tk Version8.2.0
Tcl TkTcl Tk Version8.2.1
Tcl TkTcl Tk Version8.2.2
Tcl TkTcl Tk Version8.2.3
Tcl TkTcl Tk Version8.3.0
Tcl TkTcl Tk Version8.3.1
Tcl TkTcl Tk Version8.3.2
Tcl TkTcl Tk Version8.3.3
Tcl TkTcl Tk Version8.3.4
Tcl TkTcl Tk Version8.3.5
Tcl TkTcl Tk Version8.4.0
Tcl TkTcl Tk Version8.4.1
Tcl TkTcl Tk Version8.4.2
Tcl TkTcl Tk Version8.4.3
Tcl TkTcl Tk Version8.4.4
Tcl TkTcl Tk Version8.4.5
Tcl TkTcl Tk Version8.4.6
Tcl TkTcl Tk Version8.4.7
Tcl TkTcl Tk Version8.4.8
Tcl TkTcl Tk Version8.4.9
Tcl TkTcl Tk Version8.4.10
Tcl TkTcl Tk Version8.4.11
Tcl TkTcl Tk Version8.4.12
Tcl TkTcl Tk Version8.4.13
Tcl TkTcl Tk Version8.4.14
Tcl TkTcl Tk Version8.4.15
Tcl TkTcl Tk Version8.4.16
Tcl TkTcl Tk Version8.4a2
Tcl TkTcl Tk Version8.4a3
Tcl TkTcl Tk Version8.4a4
Tcl TkTcl Tk Version8.4b1
Tcl TkTcl Tk Version8.4b2
Tcl TkTcl Tk Version8.5.0
Tcl TkTcl Tk Version8.5_a3
Tcl TkTcl Tk Version8.5a1
Tcl TkTcl Tk Version8.5a2
Tcl TkTcl Tk Version8.5a3
Tcl TkTcl Tk Version8.5a4
Tcl TkTcl Tk Version8.5a5
Tcl TkTcl Tk Version8.5a6
Tcl TkTcl Tk Version8.5b1
Tcl TkTcl Tk Version8.5b2
Tcl TkTcl Tk Version8.5b3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.39% 0.905
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.