CVE-2023-3291
published 2023-06-16CVE-2023-3291: Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
PriorityP410low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.40%
32.4th percentile
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gpac | — | — |
| gpac | gpac | < 2.2.2 | 2.2.2 |
| gpac | gpac_gpac | >= unspecified < 2.2.2 | 2.2.2 |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2023-10-18
vendor_jenkins·2023-10-18·CVSS 7.5
CVE-2023-36478 [HIGH] Jenkins Security Advisory 2023-10-18
Title: Jenkins Security Advisory 2023-10-18
Jenkins Security Advisory 2023-10-18
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Descriptions
HTTP/2 denial of service vulnerabilities in bundled Jetty
SECURITY-3291
/
CVE-2023-36478, CVE-2023-44487
Severity (CVSS):
High
Description:
Jenkins b
Debian
CVE-2023-3291: gpac - Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
vendor_debian·2023·CVSS 3.3
CVE-2023-3291 [LOW] CVE-2023-3291: gpac - Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
Scope: local
bullseye: open
OSV
CVE-2023-3291: Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2
osv·2023-06-16·CVSS 3.3
CVE-2023-3291 [LOW] CVE-2023-3291: Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
GHSA
GHSA-9pv7-q9jh-w7p4: Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2
ghsa_unreviewed·2023-06-16
CVE-2023-3291 [MEDIUM] CWE-122 GHSA-9pv7-q9jh-w7p4: Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
No detection rules found.
No public exploits indexed.
https://github.com/gpac/gpac/commit/6a748ccc3f76ff10e3ae43014967ea4b0c088aafhttps://huntr.dev/bounties/526954e6-8683-4697-bfa2-886c3204a1d5https://www.debian.org/security/2023/dsa-5452https://github.com/gpac/gpac/commit/6a748ccc3f76ff10e3ae43014967ea4b0c088aafhttps://huntr.dev/bounties/526954e6-8683-4697-bfa2-886c3204a1d5https://www.debian.org/security/2023/dsa-5452
2023-06-16
Published