PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This vulnerability has a 18.20% probability of being exploited in the next 30 days, ranking higher than 97% of all scored CVEs.