8.8
CVSSv3

CVE-2021-27229

Published: 16/02/2021 Updated: 06/05/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mumble prior to 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mumble mumble

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #982904 mumble: CVE-2021-27229 Package: src:mumble; Maintainer for src:mumble is Christopher Knadle <ChrisKnadle@coredumpus>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 16 Feb 2021 09:24:02 UTC Severity: grave Tags: security, upstream Found in version mumble/133-1 ...
Mumble before 134 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text ...