Vulnerabilities
13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-43665 | A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A specially-crafted PE file can lead to killing target process. An attacker can provide a malicious file to trigger this vulnerability. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-32543 +1 in the same advisory: …29886 | An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2017-20125 +1 in the same advisory: …20124 | A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2022-21147 | An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7. An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7. A specially-crafted PE file can trigger this vulnerability to cause denial of service and termination of malware scan. An attacker can provide a malicious file to trigger this vulnerability. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2020-15535 | An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2019-12810 | A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in code execution. By persuading a victim to open a specially-crafted .PSD file, an attacker could execute arbitrary code. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2019-12808 | ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can overwrite an executable that is launched as a service to exploit this vulnerability and execute arbitrary code with system privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2019-12807 | Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archi Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format. By persuading a victim to open a specially-crafted ISO archive file, an attacker could execution arbitrary code. NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2018-5196 | Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker could execute arbitrary code execution. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2018-10027 | ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific directory: ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific directory: %PROGRAMFILES%\ESTsoft\ALZip\Formats, %PROGRAMFILES%\ESTsoft\ALZip\Coders, %PROGRAMFILES(X86)%\ESTsoft\ALZip\Formats, or %PROGRAMFILES(X86)%\ESTsoft\ALZip\Coders. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2017-11323 | Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device file, as demonstrate Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device file, as demonstrated by use of "AUX" as the initial substring of a filename. NVD description · AI analysis pending | 7.8 | 3% | PoC |
| — |