CVE: CVE-2006-4024

Export to Word

The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative LoadAddr value in a HES file, which is used as an offset in a memcpy operation and leads to a buffer underflow.

Threat-Mapped Scoring

Score: 1.9

Priority: P3 - Important (Medium)

EPSS

Score: 0.05379
Percentile: 0.89661

CVSS Scoring

CVSS v2 Score: 7.5

Severity:

Affected Products

← Back to Home