CVE-2016-20045

HNB Organizer 1.9.18-10 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -rc command-line parameter. Attackers can craft a malicious input string exceeding 108 bytes containing shellcode and a return address to overwrite the stack and achieve code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hnb_project:hierarchical_notebook:*:*:*:*:*:*:*:*

History

08 Apr 2026, 20:41

Type Values Removed Values Added
CPE cpe:2.3:a:hnb_project:hierarchical_notebook:*:*:*:*:*:*:*:*
First Time Hnb Project hierarchical Notebook
Hnb Project
Summary
  • (es) HNB Organizer 1.9.18-10 contiene una vulnerabilidad de desbordamiento de búfer local que permite a atacantes locales ejecutar código arbitrario al proporcionar un argumento de tamaño excesivo al parámetro de línea de comandos -rc. Los atacantes pueden crear una cadena de entrada maliciosa que exceda los 108 bytes que contenga shellcode y una dirección de retorno para sobrescribir la pila y lograr la ejecución de código.
References () http://hnb.sourceforge.net/ - () http://hnb.sourceforge.net/ - Product
References () https://www.exploit-db.com/exploits/40025 - () https://www.exploit-db.com/exploits/40025 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/hnb-organizer-10-local-buffer-overflow-via-rc-parameter - () https://www.vulncheck.com/advisories/hnb-organizer-10-local-buffer-overflow-via-rc-parameter - Third Party Advisory

28 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-28 12:16

Updated : 2026-04-08 20:41


NVD link : CVE-2016-20045

Mitre link : CVE-2016-20045

CVE.ORG link : CVE-2016-20045


JSON object : View

Products Affected

hnb_project

  • hierarchical_notebook
CWE
CWE-787

Out-of-bounds Write