ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-3973
+2 in the same advisory: …3976 …3980
An exploitable out of bounds write exists in the CAL parsing functionality of Canvas Draw version 5.0.0.

An exploitable out of bounds write exists in the CAL parsing functionality of Canvas Draw version 5.0.0. A specially crafted CAL image processed via the application can lead to an out of bounds write overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.

NVD description · AI analysis pending
7.82% PoC
  • canvasgfx canvas draw
CVE-2018-3981
An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0.

An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.

NVD description · AI analysis pending
7.82% PoC ×2
  • canvasgfx canvas draw