CVE-2021-28874 is a high-severity buffer overflow vulnerability (CVSS 7.8) affecting SerenityOS, specifically in its LibTextCode component. This flaw allows an attacker to achieve high confidentiality, integrity, and availability impacts by tricking a user into opening a specially crafted file. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the vulnerability has been patched in SerenityOS as of commit c9f25bca048443e317f1994ba9b106f2386688c3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2021-03-15CPE matchmatch criteria | cpe:2.3:o:serenityos:serenityos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.