Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2025-42971 | First vendor Publication | 2025-07-08 |
Vendor | Cve | Last vendor Modification | 2025-07-08 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L | |||
---|---|---|---|
Overall CVSS Score | 4 | ||
Base Score | 4 | Environmental Score | 4 |
impact SubScore | 3.4 | Temporal Score | 4 |
Exploitabality Sub Score | 0.6 | ||
Attack Vector | Local | Attack Complexity | Low |
Privileges Required | High | User Interaction | Required |
Scope | Unchanged | Confidentiality Impact | Low |
Integrity Impact | Low | Availability Impact | Low |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : | |||
---|---|---|---|
Cvss Base Score | N/A | Attack Range | N/A |
Cvss Impact Score | N/A | Attack Complexity | N/A |
Cvss Expoit Score | N/A | Authentication | N/A |
Calculate full CVSS 2.0 Vectors scores |
Detail
A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it gets processed by SAPCAR on their system, resulting in out-of-bounds memory read and write. This could lead to file extraction and file overwrite outside the intended directories. This vulnerability has low impact on the confidentiality, integrity and availability of the application. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-42971 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-787 | Out-of-bounds Write (CWE/SANS Top 25) |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2025-07-08 09:20:35 |
|