9.8
CVE-2019-12553
- EPSS 1.8%
- Veröffentlicht 05.06.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:23:05
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sweetscape ≫ 010 Editor Version9.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.8% | 0.811 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.