Showing 1 vulnerability on this page for Bindiff

Signals CISA KEV Ransomware Nuclei
Google LLC vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Use-after-free in BinDiff

An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset. This can allow the attacker to control the instruction pointer and execute arbitrary code. It is recommended to upgrade BinDiff 7

CWE-416Jun 29, 2021
CVSS7.5v3.1EPSS0.207%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX