Vulnerabilities (CVE)

Filtered by vendor Nethack Subscribe
Filtered by product Nethack
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5254 1 Nethack 1 Nethack 2020-03-20 6.8 MEDIUM 8.1 HIGH
In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue.
CVE-2020-5210 1 Nethack 1 Nethack 2020-02-03 4.6 MEDIUM 7.8 HIGH
In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options. Users should upgrade to NetHack 3.6.5.
CVE-2020-5209 1 Nethack 1 Nethack 2020-02-03 4.6 MEDIUM 7.8 HIGH
In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options. Users should upgrade to NetHack 3.6.5.