CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
libmysofa is vulnerable to Heap-based Buffer Overflow | 9.8 |
Critique |
||
hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json. | 8.8 |
Haute |
||
libmysofa before 2019-11-24 does not properly restrict recursive function calls, as demonstrated by reports of stack consumption in readOHDRHeaderMessageDatatype in dataobject.c and directblockRead in fractalhead.c. NOTE: a download of v0.9 after 2019-12-06 should fully remediate this issue. | 6.5 |
Moyen |
||
treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions. | 9.8 |
Critique |