Vulnerabilities
18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44506 +1 in the same advisory: …44505 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2021-44486 | An issue was discovered in YottaDB through r1.32 and V7.0-000. An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c in order to gain control of the flow of execution. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2021-27377 | An issue was discovered in the yottadb crate before 1.2.0 for Rust. An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_next_st and ydb_subscript_prev_st have a use-after-free. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — |