CVE-2023-53966
CRITICALDescription
SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to potentially execute arbitrary code and crash the application.
Is your site exposed to CVE-2023-53966?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sound4 | linkandshare_transmitter |
References
Exploits
Frequently Asked Questions
What is CVE-2023-53966? +
How severe is CVE-2023-53966? +
What products are affected by CVE-2023-53966? +
How do I check if I'm vulnerable to CVE-2023-53966? +
Related Vulnerabilities
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly …
In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan …
WM Downloader version 3.1.2.2 is vulnerable to a buffer overflow when processing a specially crafted .m3u playlist file. The application …
Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing …
ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending …
A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort …