Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21683
HistoryOct 11, 2019 - 5:12 a.m.

Remote Code Execution (RCE)

2019-10-1105:12:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.021

Percentile

89.3%

chakracore is vulnerable to remote code execution (RCE). The vulnerability exists in lib/Backend/GlobOpt.cpp where there was a memory issue in using src2 as the induction sym. This CVE ID is different from CVE-2019-1307, CVE-2019-1308, CVE-2019-1366.