Two high-severity vulnerabilities have been documented in the TiEmu calculator emulator, affecting TiEmu 3.03-nogdb+dfsg-3 and TiEmu 2.08 and earlier. The flaws, tracked as CVE-2016-20040 and CVE-2017-20225, are stack-based buffer overflows triggered through crafted command-line input. In the newer case, an oversized ROM parameter passed to the tiemu CLI can cause a stack overflow, potentially crashing the application or allowing arbitrary code execution.
The older issue similarly stems from insufficient bounds checking on user-controlled arguments and may permit arbitrary code execution in the context of the application. The published records classify the weakness as CWE-787 and note that exploitation could leverage techniques such as ROP to bypass protections and execute shellcode. Both CVE entries include severity scoring and references to external advisories and exploit material, indicating that locally supplied malicious input is sufficient to corrupt memory in affected TiEmu versions.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE record was received for a locally exploitable buffer overflow in TiEmu 3.03-nogdb+dfsg-3 triggered by an oversized ROM parameter passed to the tiemu command-line interface. The published details say the stack overflow could crash the application or potentially allow arbitrary code execution.
A CVE record was received for a stack-based buffer overflow affecting TiEmu 2.08 and earlier, caused by insufficient boundary checks on command-line input. The entry states the flaw could enable arbitrary code execution, including via ROP-assisted shellcode execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.