CVE-2013-7386

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
02/06/2014
Last modified:
08/07/2025

Description

Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the gui_urls item in an account file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:universityofcalifornia:boinc_client:7.2.33:*:*:*:*:*:*:*