4Mhz Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with 4Mhz products.
Products
- B64dec1 vulnerability
- Base64 Decoder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25634HIGH | Base64 Decoder 1.1.2 Local Buffer Overflow SEH EgghunterBase64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input file that overflows a buffer, overwrites the SEH chain with a POP-POP-RET gadget address, and uses an egghunter payload to locate and execute shellcode for code execution. CWE-787Mar 24, 2026 | CVSS8.6v4.0 | EPSS0.262% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37124HIGH | B64dec 1.1.2 - Buffer Overflow (SEH Overflow + Egg Hunter)B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) with crafted input. Attackers can leverage an egg hunter technique and carefully constructed payload to inject and execute malicious code during base64 decoding process. CWE-121Feb 5, 2026 | CVSS8.4v4.0 | EPSS0.353% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |