Vulnerabilities > Call CC > Chicken

DATE CVE VULNERABILITY TITLE RISK
2017-03-29 CVE-2015-4556 Improper Input Validation vulnerability in Call-Cc Chicken 4.8.0/4.9.0
The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (crash).
network
low complexity
call-cc CWE-20
5.0
2017-03-16 CVE-2017-6949 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Call-Cc Chicken 4.12.0
An issue was discovered in CHICKEN Scheme through 4.12.0.
network
call-cc CWE-119
6.8
2017-01-10 CVE-2016-6831 Resource Exhaustion vulnerability in Call-Cc Chicken
The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak.
network
low complexity
call-cc CWE-400
5.0
2017-01-10 CVE-2016-6830 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Call-Cc Chicken
The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment variables to use in its execve() call.
network
low complexity
call-cc CWE-119
7.5
2015-08-28 CVE-2014-9651 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Call-Cc Chicken 4.10.0/4.9.0/4.9.0.1
Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecified impact via a positive START argument to the "substring-index[-ci] procedures."
network
low complexity
call-cc CWE-119
7.5
2013-10-09 CVE-2013-4385 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Call-Cc Chicken
Buffer overflow in the "read-string!" procedure in the "extras" unit in CHICKEN stable before 4.8.0.5 and development snapshots before 4.8.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via a "#f" value in the NUM argument.
network
low complexity
call-cc CWE-119
7.5