5

CVE-2014-3756

The client in Mumble 1.2.x before 1.2.6 allows remote attackers to force the loading of an external file and cause a denial of service (hang and resource consumption) via a crafted string that is treated as rich-text by a Qt widget, as demonstrated by the (1) user or (2) channel name in a Qt dialog, (3) subject common name or (4) email address to the Certificate Wizard, or (5) server name in a tooltip.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MumbleMumble Version1.2.0
MumbleMumble Version1.2.1
MumbleMumble Version1.2.2
MumbleMumble Version1.2.3
MumbleMumble Version1.2.3 Updaterc1
MumbleMumble Version1.2.3 Updaterc2
MumbleMumble Version1.2.3 Updaterc3
MumbleMumble Version1.2.4
MumbleMumble Version1.2.4 Updatebeta1
MumbleMumble Version1.2.4 Updaterc1
MumbleMumble Version1.2.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.687
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P