CVE-2023-1570 is a heap-based buffer overflow vulnerability found in the __interceptor_memcpy function within the tiny_dng_loader.h file of syoyo tinydng. This issue, affecting tinydng_project tinydng, requires local access for exploitation. With a CVSS score of 5.5 (Medium), it has low attack complexity and no user interaction, potentially leading to high availability impact. While the exploit has been publicly disclosed, there is no evidence of active exploitation, nor are there Metasploit, Nuclei, or ExploitDB modules available, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-02-20CPE matchmatch criteria | cpe:2.3:a:tinydng_project:tinydng:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.