ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-5038
+2 in the same advisory: …5039 …5040
An exploitable command execution vulnerability exists in the print-tlv command of Weave tool.

An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a specially crafted Weave command.

NVD description · AI analysis pending
8.8
group max
3% PoC
  • openweave openweave-core