Vulnerabilities > Call CC

DATE CVE VULNERABILITY TITLE RISK
2022-12-10 CVE-2022-45145 OS Command Injection vulnerability in Call-Cc Chicken
egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.
network
low complexity
call-cc CWE-78
critical
9.8
2019-11-22 CVE-2014-6310 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.
network
low complexity
call-cc debian CWE-120
critical
9.8
2019-10-31 CVE-2013-2075 Classic Buffer Overflow vulnerability in Call-Cc Chicken
Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.
network
low complexity
call-cc CWE-120
8.8
2019-10-31 CVE-2012-6125 Improper Input Validation vulnerability in Call-Cc Chicken
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
network
low complexity
call-cc CWE-20
critical
9.8
2019-10-31 CVE-2012-6124 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Call-Cc Chicken
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value.
network
low complexity
call-cc CWE-338
5.3
2019-10-31 CVE-2012-6123 Improper Input Validation vulnerability in multiple products
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
network
low complexity
call-cc debian CWE-20
6.5
2019-10-31 CVE-2012-6122 Classic Buffer Overflow vulnerability in Call-Cc Chicken
Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.
network
low complexity
call-cc CWE-120
7.5
2019-10-31 CVE-2013-2024 OS Command Injection vulnerability in multiple products
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
network
low complexity
call-cc debian CWE-78
8.8
2017-07-17 CVE-2017-11343 Algorithmic Complexity vulnerability in Call-Cc Chicken
Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to an algorithmic complexity attack.
network
low complexity
call-cc CWE-407
7.5
2017-06-07 CVE-2015-8235 Path Traversal vulnerability in Call-Cc Spiffy
Directory traversal vulnerability in Spiffy before 5.4.
network
low complexity
call-cc CWE-22
7.5