VYPR
Vendor

Flightgear

Products
2
CVEs
6
Across products
8
Status
Private

Products

2

Recent CVEs

6
  • CVE-2017-13709HigAug 27, 2017
    risk 0.49cvss 7.5epss 0.01

    In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the contents of the global Property Tree.

  • CVE-2017-8921HigMay 12, 2017
    risk 0.49cvss 7.5epss 0.01

    In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage…

  • CVE-2016-9956HigFeb 22, 2017
    risk 0.49cvss 7.5epss 0.03

    The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.

  • CVE-2012-2091Jun 17, 2012
    risk 0.01cvss epss 0.06

    Multiple buffer overflows in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long string in a rotor tag of an aircraft xml model to the…

  • CVE-2025-0781HigJan 28, 2025
    risk 0.00cvss 8.6epss 0.00

    An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.

  • CVE-2012-2090Jun 17, 2012
    risk 0.00cvss epss 0.06

    Multiple format string vulnerabilities in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in certain data chunk values in an aircraft xml…