Vulnerability Description
Scalabium dBase Viewer version 2.6 (Build 5.751) is vulnerable to remote code execution via a crafted DBF file that triggers a buffer overflow. An attacker can use the Structured Exception Handler (SEH) records and redirect execution to attacker-controlled code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Scalabium | Dbase Viewer | 2.6 |
Related Weaknesses (CWE)
References
- https://govtech-csg.github.io/security-advisories/2021/09/18/CVE-2021-35297.htmlThird Party Advisory
- https://govtech-csg.github.io/security-advisories/2021/09/18/CVE-2021-35297.htmlThird Party Advisory
FAQ
What is CVE-2021-35297?
CVE-2021-35297 is a vulnerability with a CVSS score of 7.8 (HIGH). Scalabium dBase Viewer version 2.6 (Build 5.751) is vulnerable to remote code execution via a crafted DBF file that triggers a buffer overflow. An attacker can use the Structured Exception Handler (SE...
How severe is CVE-2021-35297?
CVE-2021-35297 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-35297?
Check the references section above for vendor advisories and patch information. Affected products include: Scalabium Dbase Viewer.