CVE-2016-20038 - Vulnerability Analysis
HighCVSS: 8.4Last Updated: March 28, 2026
yTree - Buffer Overflow
Published: March 28, 2026Updated: March 28, 2026
Overview
yTree 1.94-1.1 contains a buffer overflow caused by an excessively long argument, letting local attackers execute arbitrary code by overwriting the stack with crafted input, exploit requires local access.
Severity & Score
Severity: High
CVSS Score: 8.4
Impact
Local attackers can execute arbitrary code, potentially gaining full control of the application.
Mitigation
Update to the latest version or apply vendor patches addressing the buffer overflow.
References
Related Resources
Details
- CVE ID
- CVE-2016-20038
- Severity
- High
- CVSS Score
- 8.4
- Type
- buffer_overflow
- Status
- new
CWE
- CWE-787
CVSS Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H