LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2016-20038

CVE-2016-20038 - Vulnerability Analysis

HighCVSS: 8.4

Last Updated: March 28, 2026

yTree - Buffer Overflow

Published: March 28, 2026Updated: March 28, 2026

Overview

yTree 1.94-1.1 contains a buffer overflow caused by an excessively long argument, letting local attackers execute arbitrary code by overwriting the stack with crafted input, exploit requires local access.

Severity & Score

Severity: High
CVSS Score: 8.4

Impact

Local attackers can execute arbitrary code, potentially gaining full control of the application.

Mitigation

Update to the latest version or apply vendor patches addressing the buffer overflow.

Details

CVE ID
CVE-2016-20038
Severity
High
CVSS Score
8.4
Type
buffer_overflow
Status
new

CWE

  • CWE-787

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H