CVE-2024-5436 Vulnerability Details

  /     /     /  

CVE-2024-5436 Metadata Quick Info

CVE Published: 31/05/2024 | CVE Updated: 01/08/2024 | CVE Year: 2024
Source: Google | Vendor: Snap | Product: Snapchat Lenscore
Status : PUBLISHED

CVE-2024-5436 Description

Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-704
CWE Name: CWE-704 Incorrect Type Conversion or Cast
Source: Snap

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-253
CAPEC Description: CAPEC-253 Remote Code Inclusion


Source: NVD (National Vulnerability Database).