6.8
CVSSv2

CVE-2016-8714

Published: 10/03/2017 Updated: 14/12/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An attacker can send a malicious R script to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

r project r 3.3.0

r project r 3.3.2

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #857466 r-base: CVE-2016-8714: R: Buffer overflow in the LoadEncoding functionality Package: src:r-base; Maintainer for src:r-base is Dirk Eddelbuettel <edd@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 11 Mar 2017 17:00:01 UTC Severity: grave Tags: fixed-upstr ...