V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-5461
DEB
Medium

Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial…

CVSS
4.4
Medium
EPSS
0.12
p95
Published
2014-01-01
Updated
2014-01-01
Description

Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.

Tags · CWE
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Lua5.1Lua5.1Lua5.1Lua5.1Lua5.1Lua5.1Lua5.1Lua5.1Lua5.2Lua5.2Lua5.2Lua5.2Lua5.2Lua5.2Lua5.2Lua5.2Lua50Lua50Lua50Lua50
CVSS vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.116 · p95
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
lua5.1Tracked
lua5.1Tracked
lua5.1Tracked
lua5.1Tracked
lua5.1Tracked
lua5.1Tracked
lua5.1Tracked
lua5.1Tracked
lua5.2Tracked
lua5.2Tracked
lua5.2Tracked
lua5.2Tracked
lua5.2Tracked
lua5.2Tracked
lua5.2Tracked
lua5.2Tracked
lua50Tracked
lua50Tracked
lua50Tracked
lua50Tracked
Showing first 20 of 28
Source databases
DEB
CVE
UBU
Related vulnerabilities