CVE-2018-25224 identifies a stack-based buffer overflow vulnerability in PMS 0.42, which allows local unauthenticated attackers to execute arbitrary code by supplying malicious, oversized input within configuration files. Rated 8.4 High on CVSS, this vulnerability has a local attack vector with low attack complexity, enabling full compromise of confidentiality, integrity, and availability through return-oriented programming gadgets. Currently, there is no evidence of active exploitation, nor are public exploits available in common databases like Metasploit or ExploitDB, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.42CPE matchmatch criteria | cpe:2.3:a:kimtore:practical_music_search:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.