CVE-2016-20041 identifies a high-severity buffer overflow vulnerability in Yasr version 0.6.9-5, where an oversized argument supplied to the '-p' parameter can lead to application crashes or arbitrary code execution. With a CVSS v3.1 score of 8.4 (High), this flaw requires local access to the system (AV:L) but has low exploitation complexity (AC:L). Successful exploitation grants attackers high impact on confidentiality, integrity, and availability, allowing for potential system compromise. Despite its critical nature, there is currently no evidence of active exploitation, public exploit code availability (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Yasr | Yasr Screen Reader | 0.6.9-5CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.