5.5
CVE-2019-18359
- EPSS 0.5%
- Veröffentlicht 23.10.2019 20:15:14
- Zuletzt bearbeitet 21.11.2024 04:33:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application crash, which leads to remote denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Glensawyer ≫ Mp3gain Version1.6.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.653 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.