Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000437
Reference (s):
- https://github.com/marcobambini/gravity/issues/186