ZeroHour

CVE-2021-26567

CVSS 3.1
7.8 high
EPSS
1%p64
Published
()
Modified
Description

Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options.

Vendors
synologyfaad2 project
Products
diskstation manager, vs960hd firmware, skynas firmware, diskstation manager unified controller, faad2
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.