← Retour aux CVEs
CVE-2017-20227
CRITICAL9.8
Description
JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and execute a return-oriented programming chain that spawns a shell.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie3/28/2026
Derniere modification3/30/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-787
References
http://www.varaneckas.com/jad/(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/42255(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/jad-8e-1kali1-stack-based-buffer-overflow(disclosure@vulncheck.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.