CVE-2015-4646
- EPSS 1.05%
- Veröffentlicht 13.04.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.
CVE-2015-4645
- EPSS 0.21%
- Veröffentlicht 17.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.
CVE-2012-4024
- EPSS 2.29%
- Veröffentlicht 19.07.2012 19:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in ...
CVE-2012-4025
- EPSS 2.35%
- Veröffentlicht 19.07.2012 19:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer ov...