CVE-2023-40889 is a critical heap-based buffer overflow vulnerability in the qr_reader_match_centers function of ZBar 0.23.90, affecting the zbar_project zbar product. This flaw can be triggered by specially crafted QR codes, either digitally inputted or physically scanned, leading to potential information disclosure or arbitrary code execution. With a CVSS score of 9.8 (CRITICAL), it presents a high-severity risk due to its network-based attack vector, low attack complexity, and complete compromise potential (C:H/I:H/A:H). Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low current exploitation profile.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.23.90CPE matchmatch criteria | cpe:2.3:a:zbar_project:zbar:0.23.90:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025Heap-based buffer overflow in ZBar
Aug 29, 2023