FreedroidCVEs & Vulnerabilities
2 CVEs affecting Freedroid products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
freedroidrpg 2
CVE-2020-14939HIGH
An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading.
23 Jun 2020
7.8
CVSS
CVE-2020-14938CRITICAL
An issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It copies data from a file into a fixed-size heap-allocated buffer without size verification, leading to a heap-based buffer overflow.
23 Jun 2020
9.8
CVSS
← PrevPage 1 / 1Next →