CVE-2016-20049

JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 8150 bytes to overflow the stack, overwrite return addresses, and execute shellcode in the application context.
Configurations

Configuration 1 (hide)

cpe:2.3:a:varaneckas:jad_java_decompiler:1.5.8e-1kali1:*:*:*:*:*:*:*

History

22 Apr 2026, 13:58

Type Values Removed Values Added
Summary
  • (es) JAD 1.5.8e-1kali1 y versiones anteriores contiene una vulnerabilidad de desbordamiento de búfer basado en pila que permite a los atacantes ejecutar código arbitrario al proporcionar una entrada sobredimensionada que excede los límites del búfer. Los atacantes pueden crear cadenas de entrada maliciosas que excedan los 8150 bytes para desbordar la pila, sobrescribir direcciones de retorno y ejecutar shellcode en el contexto de la aplicación.
References () http://www.varaneckas.com/jad/ - () http://www.varaneckas.com/jad/ - Product
References () https://www.exploit-db.com/exploits/42076 - () https://www.exploit-db.com/exploits/42076 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/jad-8e-1kali1-stack-based-buffer-overflow-remote-code-execution - () https://www.vulncheck.com/advisories/jad-8e-1kali1-stack-based-buffer-overflow-remote-code-execution - Third Party Advisory
First Time Varaneckas
Varaneckas jad Java Decompiler
CPE cpe:2.3:a:varaneckas:jad_java_decompiler:1.5.8e-1kali1:*:*:*:*:*:*:*

28 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-28 12:16

Updated : 2026-04-22 13:58


NVD link : CVE-2016-20049

Mitre link : CVE-2016-20049

CVE.ORG link : CVE-2016-20049


JSON object : View

Products Affected

varaneckas

  • jad_java_decompiler
CWE
CWE-787

Out-of-bounds Write