CVE-2017-20227

JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and execute a return-oriented programming chain that spawns a shell.
Configurations

Configuration 1 (hide)

cpe:2.3:a:varaneckas:jad_java_decompiler:1.5.8e-1kali1:*:*:*:*:*:*:*

History

08 Apr 2026, 19:37

Type Values Removed Values Added
Summary
  • (es) JAD Java Decompiler 1.5.8e-1kali1 y versiones anteriores contiene una vulnerabilidad de desbordamiento de búfer basado en pila que permite a los atacantes ejecutar código arbitrario al proporcionar una entrada excesivamente larga que excede los límites del búfer. Los atacantes pueden crear una entrada maliciosa pasada al comando jad para desbordar la pila y ejecutar una cadena de programación orientada a retorno que genera un shell.
CPE cpe:2.3:a:varaneckas:jad_java_decompiler:1.5.8e-1kali1:*:*:*:*:*:*:*
References () http://www.varaneckas.com/jad/ - () http://www.varaneckas.com/jad/ - Product
References () https://www.exploit-db.com/exploits/42255 - () https://www.exploit-db.com/exploits/42255 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/jad-8e-1kali1-stack-based-buffer-overflow - () https://www.vulncheck.com/advisories/jad-8e-1kali1-stack-based-buffer-overflow - Third Party Advisory
First Time Varaneckas
Varaneckas jad Java Decompiler

28 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-28 12:16

Updated : 2026-04-08 19:37


NVD link : CVE-2017-20227

Mitre link : CVE-2017-20227

CVE.ORG link : CVE-2017-20227


JSON object : View

Products Affected

varaneckas

  • jad_java_decompiler
CWE
CWE-787

Out-of-bounds Write