Nothings stb Dok f056911 stb_dupreplace Korupcija memorije

Identifikovana je ranjivost klasifikovana kao Kritične u Nothings stb Dok f056911. Obuhvaćeno je funkcija stb_dupreplace. Promena uzrokuje Korupcija memorije. Definisanje problema putem CWE vodi do CWE-190. Objava slabosti je izvršena 04/07/2025. Ova ranjivost je registrovana kao CVE-2025-3408. Napad se može izvesti na daljinu. Napad je moguć samo unutar lokalne mreže. Postoje tehnički detalji. Нема доступног експлоита. U ovom trenutku, trenutna cena za eksploataciju može iznositi oko USD $0-$5k. Klasifikovano je kao nije definisano. Kao 0-day, procenjuje se da je cena na ilegalnom tržištu bila oko $0-$5k. Proizvod koristi rolling release pristup za stalnu isporuku, zbog čega nisu dostupni detalji o verzijama pogođenih ili ažuriranih izdanja. If you want to get best quality of vulnerability data, you may have to visit VulDB.

3 Promene · 94 Tačke podataka

PoljeKreirali
04/07/2025 13:01
Ažurira 1/2
04/08/2025 15:23
Ažurira 2/2
10/16/2025 17:22
software_vendorNothingsNothingsNothings
software_namestbstbstb
software_version<=f056911<=f056911<=f056911
software_rollingrelease111
software_functionstb_dupreplacestb_dupreplacestb_dupreplace
vulnerability_cweCWE-190 (Korupcija memorije)CWE-190 (Korupcija memorije)CWE-190 (Korupcija memorije)
vulnerability_risk222
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_prNNN
cvss3_vuldb_uiRRR
cvss3_vuldb_sUUU
cvss3_vuldb_cLLL
cvss3_vuldb_iLLL
cvss3_vuldb_aLLL
cvss3_vuldb_rcRRR
source_cveCVE-2025-3408CVE-2025-3408CVE-2025-3408
cna_responsibleVulDBVulDBVulDB
response_summaryThe vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.
cvss2_vuldb_avNNN
cvss2_vuldb_acLLL
cvss2_vuldb_auNNN
cvss2_vuldb_ciPPP
cvss2_vuldb_iiPPP
cvss2_vuldb_aiPPP
cvss2_vuldb_rcURURUR
cvss4_vuldb_avNNN
cvss4_vuldb_acLLL
cvss4_vuldb_prNNN
cvss4_vuldb_uiPPP
cvss4_vuldb_vcLLL
cvss4_vuldb_viLLL
cvss4_vuldb_vaLLL
cvss2_vuldb_eNDNDND
cvss2_vuldb_rlNDNDND
cvss3_vuldb_eXXX
cvss3_vuldb_rlXXX
cvss4_vuldb_atNNN
cvss4_vuldb_scNNN
cvss4_vuldb_siNNN
cvss4_vuldb_saNNN
cvss4_vuldb_eXXX
cvss2_vuldb_basescore7.57.57.5
cvss2_vuldb_tempscore7.17.17.1
cvss3_vuldb_basescore6.36.36.3
cvss3_vuldb_tempscore6.16.16.1
cvss3_meta_basescore6.36.37.1
cvss3_meta_tempscore6.16.27.1
cvss4_vuldb_bscore5.35.35.3
cvss4_vuldb_btscore5.35.35.3
advisory_date1743976800 (04/07/2025)1743976800 (04/07/2025)1743976800 (04/07/2025)
price_0day$0-$5k$0-$5k$0-$5k
cve_nvd_summaryA vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation leads to integer overflow. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation leads to integer overflow. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
cve_nvd_summaryesSe encontró una vulnerabilidad en Nothings stb hasta f056911. Se ha clasificado como crítica. Este problema afecta a la función stb_dupreplace. La manipulación provoca un desbordamiento de enteros. El ataque puede ejecutarse remotamente. Este producto utiliza un sistema de entrega continua con versiones progresivas. Por lo tanto, no se dispone de detalles de las versiones afectadas ni de las versiones actualizadas. Se contactó al proveedor con antelación para informarle sobre esta divulgación, pero no respondió.Se encontró una vulnerabilidad en Nothings stb hasta f056911. Se ha clasificado como crítica. Este problema afecta a la función stb_dupreplace. La manipulación provoca un desbordamiento de enteros. El ataque puede ejecutarse remotamente. Este producto utiliza un sistema de entrega continua con versiones progresivas. Por lo tanto, no se dispone de detalles de las versiones afectadas ni de las versiones actualizadas. Se contactó al proveedor con antelación para informarle sobre esta divulgación, pero no respondió.
cvss4_cna_avNN
cvss4_cna_acLL
cvss4_cna_atNN
cvss4_cna_prNN
cvss4_cna_uiPP
cvss4_cna_vcLL
cvss4_cna_viLL
cvss4_cna_vaLL
cvss4_cna_scNN
cvss4_cna_siNN
cvss4_cna_saNN
cvss4_cna_bscore5.35.3
cvss3_cna_avNN
cvss3_cna_acLL
cvss3_cna_prNN
cvss3_cna_uiRR
cvss3_cna_sUU
cvss3_cna_cLL
cvss3_cna_iLL
cvss3_cna_aLL
cvss3_cna_basescore6.36.3
cvss2_cna_avNN
cvss2_cna_acLL
cvss2_cna_auNN
cvss2_cna_ciPP
cvss2_cna_iiPP
cvss2_cna_aiPP
cvss2_cna_basescore7.57.5
cvss3_nvd_avN
cvss3_nvd_acL
cvss3_nvd_prN
cvss3_nvd_uiR
cvss3_nvd_sU
cvss3_nvd_cH
cvss3_nvd_iH
cvss3_nvd_aH
cvss3_nvd_basescore8.8

Are you interested in using VulDB?

Download the whitepaper to learn more about our service!