Vendor
Greenwoodsoftware
Products
1
CVEs
2
Across products
2
Status
Private
Products
1- 2 CVEs
Recent CVEs
2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-32487 | Hig | 0.00 | 8.6 | 0.01 | Apr 13, 2024 | less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation… | ||
| CVE-2022-48624 | Hig | 0.00 | 7.8 | 0.01 | Feb 19, 2024 | close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE. |
- risk 0.00cvss 8.6epss 0.01
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation…
- risk 0.00cvss 7.8epss 0.01
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.