Vulnerability Details CVE-2019-12807
Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format. By persuading a victim to open a specially-crafted ISO archive file, an attacker could execution arbitrary code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.4%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2019-12807
-
cpe:2.3:a:estsoft:alzip:10.76
-
cpe:2.3:a:estsoft:alzip:10.76.0.0
-
cpe:2.3:a:estsoft:alzip:10.81
-
cpe:2.3:a:estsoft:alzip:10.83
-
cpe:2.3:a:estsoft:alzip:8.0
-
cpe:2.3:a:estsoft:alzip:8.12
-
cpe:2.3:a:estsoft:alzip:8.21
-
cpe:2.3:a:estsoft:alzip:8.5.1
-
cpe:2.3:a:estsoft:alzip:8.51
-
cpe:2.3:o:microsoft:windows:-