Greenwoodsoftware's vulnerability profile centers on its LESS product and exhibits a pattern of input-handling and code-injection weaknesses, including OS command injection and static code injection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Greenwoodsoftware over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32487HIGH less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with at | Apr 13, 2024 | 8.6 | 21 | NO | NO |
CVE-2022-48624HIGH close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE. | Feb 19, 2024 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Greenwoodsoftware.
Media articles that mention a CVE ID that affects a product developed by Greenwoodsoftware — matched by CVE ID, not by vendor name.