Vulnerabilities > Nasa

DATE CVE VULNERABILITY TITLE RISK
2018-08-01 CVE-2018-3847 Out-of-bounds Write vulnerability in Nasa Cfitsio 3.42
Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42.
network
low complexity
nasa CWE-787
8.8
2018-04-16 CVE-2018-3849 Out-of-bounds Write vulnerability in multiple products
In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data.
network
low complexity
nasa fedoraproject CWE-787
8.8
2018-04-16 CVE-2018-3848 Out-of-bounds Write vulnerability in multiple products
In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data.
network
low complexity
nasa fedoraproject CWE-787
8.8
2018-04-16 CVE-2018-3846 Out-of-bounds Write vulnerability in multiple products
In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data.
network
low complexity
nasa fedoraproject CWE-787
8.8
2018-02-09 CVE-2018-1000048 Deserialization of Untrusted Data vulnerability in Nasa Rtretrievalframework 1.0
NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in remote code execution.
network
low complexity
nasa CWE-502
8.8
2018-02-09 CVE-2018-1000047 Deserialization of Untrusted Data vulnerability in Nasa Kodiak 1.0
NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution.
network
low complexity
nasa CWE-502
8.8
2018-02-09 CVE-2018-1000046 Deserialization of Untrusted Data vulnerability in Nasa Pyblock 1.0/1.3
NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution.
local
low complexity
nasa CWE-502
7.8
2018-02-09 CVE-2018-1000045 Deserialization of Untrusted Data vulnerability in Nasa Singledop 1.0
NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution.
local
low complexity
nasa CWE-502
7.8