CVE-2014-8322
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 24%
from disclosure to weapon0 days
Published on NVDJan 31
1st PoCOct 20
exploitation probability
24%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/128943/Aircrack-ng-1.2-Beta-3-DoS-Code-Execution.htmlunverifiedcve_referencewww.exploit-db.com/exploits/35018unverifiedexploitdbwww.exploit-db.com/exploits/35018unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://aircrack-ng.blogspot.com/2014/10/aircrack-ng-12-release-candidate-1.htmlhttp://packetstormsecurity.com/files/128943/Aircrack-ng-1.2-Beta-3-DoS-Code-Execution.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/98459https://github.com/aircrack-ng/aircrack-ng/commit/091b153f294b9b695b0b2831e65936438b550d7bhttps://github.com/aircrack-ng/aircrack-ng/pull/14http://www.exploit-db.com/exploits/35018