9.8
CVE-2023-30187
- EPSS 1.88%
- Veröffentlicht 14.08.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:59:52
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Onlyoffice ≫ Document Server Version >= 4.0.3 <= 7.3.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.88% | 0.826 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.