
Find real vulnerabilities before they ship
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
| Base Score | 4.6 |
|---|---|
| Vector String | AV:L/AC:L/Au:N/C:P/I:P/A:P |
| Base Severity | Unknown |
| Version | 2.0 |
| Attack Vector (AV) |