peter bassill · operator
$ cve CVE-2016-2195 JSON

CVE-2016-2195

9.8
CRITICAL · CVSS 3.0 · EPSS 6.7% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.68% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2016-05-13
Last modified2026-06-17

Affected (2)

VendorProduct
botan projectbotan
debiandebian linux

References

→ the Explorer  ·  watch your stack  ·  NVD