VDB
CVE-2015-8096
CVE-2015-8096
PUBLISHED
CVSS 10 CRITICAL
Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related to "phase one 0x412 tag," which triggers a heap-based buffer overflow.
EPSS 4.02% · 90.0th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
4.02%
90.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| picasa | 3.9.140 | |
| n/a | n/a | n/a |
Timeline
- Nov 9, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 20151026 Secunia Research: Google Picasa Phase One Tags Processing Integer Overflow Vulnerability mailing-list
- http://packetstormsecurity.com/files/134084/Google-Picasa-Phase-One-Tags-Processing-Integer-Overflow.html url
- https://nvd.nist.gov/vuln/detail/CVE-2015-8096 advisory
- http://secunia.com/secunia_research/2015-3 url
- http://secunia.com/secunia_research/2015-3/ technical