Lucene search

K
cveMitreCVE-2015-8221
HistoryNov 17, 2015 - 3:59 p.m.

CVE-2015-8221

2015-11-1715:59:22
CWE-119
CWE-189
mitre
web.nvd.nist.gov
898
cve-2015-8221
google
picasa
integer overflow
remote code execution
buffer overflow
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

Low

EPSS

0.025

Percentile

90.2%

Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
googlepicasaRange3.9.140
VendorProductVersionCPE
googlepicasa*cpe:2.3:a:google:picasa:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

Low

EPSS

0.025

Percentile

90.2%

Related for CVE-2015-8221