CVE-2017-7239
9.8
CRITICAL · CVSS 3.0 · EPSS 3.6% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.61% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-04-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| ninka project | ninka |
References
- http://www.openwall.com/lists/oss-security/2017/04/03/3
- http://www.securityfocus.com/bid/97325
- https://github.com/dmgerman/ninka/commit/81f185261c8863c5b84344ee31192870be939faf
- http://www.openwall.com/lists/oss-security/2017/04/03/3
- http://www.securityfocus.com/bid/97325
- https://github.com/dmgerman/ninka/commit/81f185261c8863c5b84344ee31192870be939faf
→ the Explorer · watch your stack · NVD