CVE-2020-37001

Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Frigate Professional 3.36.0.9 contiene una vulnerabilidad local de desbordamiento de búfer en la función Pack File que permite a los atacantes ejecutar código arbitrario desbordando el campo de entrada Archive To. Los atacantes pueden crear una carga útil maliciosa que sobrescribe el Structured Exception Handler (SEH) y utiliza una técnica egghunter para ejecutar una carga útil de shell inversa.

29 Jan 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-29 15:16

Updated : 2026-04-15 00:35


NVD link : CVE-2020-37001

Mitre link : CVE-2020-37001

CVE.ORG link : CVE-2020-37001


JSON object : View

Products Affected

No product.

CWE
CWE-121

Stack-based Buffer Overflow