CVE-2016-20039 identifies a buffer overflow vulnerability in Multi Emulator Super System (MESS) versions 0.154-3.1, specifically within its gamma parameter handling. This flaw allows a local attacker to provide an oversized gamma value, leading to a stack buffer overflow that can crash the application or enable arbitrary code execution. With a CVSS v3.1 score of 8.4 (High), the potential impact includes high confidentiality, integrity, and availability compromise. Despite the high severity, there is no evidence of active exploitation, public exploit code availability (e.g., Metasploit, ExploitDB), or significant community discussion, and its EPSS score indicates a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mamedev | Mess Emulator | 0.154-3.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.