E2Fsprogs Project E2Fsprogs vulnerabilities

6 known vulnerabilities affecting e2fsprogs_project/e2fsprogs.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2022-1304HIGHCVSS 7.8v1.46.5ve2fsprogs 1.46.52022-04-14
CVE-2022-1304 [HIGH] CWE-125 CVE-2022-1304: An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segme An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
cvelistv5nvdosv
CVE-2019-5188MEDIUMCVSS 6.7≥ 1.43.3, ≤ 1.45.4v1.43.3 - 1.45.42020-01-08
CVE-2019-5188 [MEDIUM] CWE-787 CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1 A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
cvelistv5nvdosv
CVE-2019-5094MEDIUMCVSS 6.7≥ 1.43.3, ≤ 1.45.3vE2fsprogs 1.43.3 - 1.45.32019-09-24
CVE-2019-5094 [MEDIUM] CWE-787 CVE-2019-5094: An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45 An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
cvelistv5nvdosv
CVE-2015-1572MEDIUMCVSS 4.6≤ 1.42.112015-02-24
CVE-2015-1572 [MEDIUM] CVE-2015-1572: Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
nvdosv
CVE-2015-0247MEDIUMCVSS 4.6≤ 1.42.112015-02-17
CVE-2015-0247 [MEDIUM] CWE-119 CVE-2015-0247: Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows l Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
nvdosv
CVE-2007-5497MEDIUMCVSS 5.8≥ 0, < 1.40.3-12007-12-07
CVE-2007-5497 [MEDIUM] CVE-2007-5497: Multiple integer overflows in libext2fs in e2fsprogs before 1 Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.
osv