cvedb.io
CVE-2021-45423
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2023-03-13T18:15:12.553 · Last modified 2026-06-17T04:13:21.750

Summary

A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Names is dynamically allocated on the stack using exp->NumberOfFunctions as its size. However, the loop uses exp->NumberOfNames to iterate over it and set its components value. Therefore, the loop code assumes that exp->NumberOfFunctions is greater than ordinal at each iteration. This can lead to arbitrary code execution.

Affected products

pev_project — pev

Does this affect you?

Add your gear to cvedb and we'll alert you only when pev_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.