CVE-2021-35297 describes a remote code execution vulnerability in Scalabium dBase Viewer version 2.6 (Build 5.751), stemming from a buffer overflow triggered by a specially crafted DBF file. This allows an attacker to redirect execution using Structured Exception Handler (SEH) records, leading to high impact on confidentiality, integrity, and availability. Rated with a CVSS score of 7.8 (High), it requires user interaction (UI:R) and local access (AV:L) for exploitation. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB: None), it is not listed in CISA's KEV catalog, and shows no active community discussion or media coverage, suggesting a low likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6CPE matchmatch criteria | cpe:2.3:a:scalabium:dbase_viewer:2.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.