Nsa

Ghidra

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.15%
  • Veröffentlicht 10.06.2026 12:43:09
  • Zuletzt bearbeitet 11.06.2026 13:28:01

Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an arbitrarily large ncmds load command co...

  • EPSS 0.31%
  • Veröffentlicht 10.06.2026 12:42:30
  • Zuletzt bearbeitet 11.06.2026 13:58:23

Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query ...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 10.06.2026 12:42:01
  • Zuletzt bearbeitet 12.06.2026 01:10:23

Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that causes stale pointers in the HighI...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 10.06.2026 12:41:39
  • Zuletzt bearbeitet 12.06.2026 01:18:06

Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations without validation. Remote attackers can connect ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 10.06.2026 12:41:11
  • Zuletzt bearbeitet 11.06.2026 19:52:18

Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filena...

  • EPSS 0.25%
  • Veröffentlicht 10.06.2026 12:40:46
  • Zuletzt bearbeitet 11.06.2026 19:52:14

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signatu...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 10.06.2026 12:40:22
  • Zuletzt bearbeitet 11.06.2026 19:52:09

Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names in binaries to trigger exponential memory allocati...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 10.06.2026 12:39:59
  • Zuletzt bearbeitet 11.06.2026 19:52:02

Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitra...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 10.06.2026 12:39:34
  • Zuletzt bearbeitet 11.06.2026 19:51:42

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when open...

  • EPSS 0.5%
  • Veröffentlicht 10.06.2026 12:39:03
  • Zuletzt bearbeitet 11.06.2026 19:51:01

Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malici...