Redhat Hivex vulnerabilities
3 known vulnerabilities affecting redhat/hivex.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2021-3622MEDIUMCVSS 4.3fixed in 1.3.21vhivex-1.3.212021-12-23
CVE-2021-3622 [MEDIUM] CWE-400 CVE-2021-3622: A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Win
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
cvelistv5nvdosv
CVE-2021-3504MEDIUMCVSS 5.4fixed in 1.3.20vhivex-1.3.202021-05-11
CVE-2021-3504 [MEDIUM] CWE-125 CVE-2021-3504: A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bound
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is
cvelistv5nvdosv
CVE-2014-9273MEDIUMCVSS 4.6≥ 0, < 1.3.11-12014-12-08
CVE-2014-9273 [MEDIUM] CVE-2014-9273: lib/handle
lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write.
osv