CVE-2022-34970
CRITICALCrow < 1.0\+4 - Buffer Overflow
Title source: ruleDescription
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.
Exploits (1)
References (4)
Scores
CVSS v3
9.8
EPSS
0.2399
EPSS Percentile
96.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-193
Status
published
Products (1)
crowcpp/crow
< 1.0\+4
Published
Aug 04, 2022
Tracked Since
Feb 18, 2026