Vulnerability Details CVE-2022-34970
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.342
EPSS Ranking 96.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-34970
-
-
cpe:2.3:a:crowcpp:crow:0.1
-
cpe:2.3:a:crowcpp:crow:0.2
-
cpe:2.3:a:crowcpp:crow:0.3
-
cpe:2.3:a:crowcpp:crow:0.3+1
-
cpe:2.3:a:crowcpp:crow:0.3+2
-
cpe:2.3:a:crowcpp:crow:0.3+3
-
cpe:2.3:a:crowcpp:crow:0.3+4
-
cpe:2.3:a:crowcpp:crow:1.0
-
cpe:2.3:a:crowcpp:crow:1.0+1
-
cpe:2.3:a:crowcpp:crow:1.0+2
-
cpe:2.3:a:crowcpp:crow:1.0+3