← Back to browse · API

CVE-2017-12087

Severity
CRITICAL
CVSS
10.0
EPSS
0.01943
Risk score
40.68
CISA KEV
No
PoC
No
Published
2018-04-24
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2017-3673, GHSA-CF6X-64RM-85PR
Products
Talos:Tinysvcmdns 2016-07-18
Sources
euvd EUVD-2017-3673

Description

An exploitable heap overflow vulnerability exists in the tinysvcmdns library version 2016-07-18. A specially crafted packet can make the library overwrite an arbitrary amount of data on the heap with attacker controlled values. An attacker needs send a dns packet to trigger this vulnerability.

References