VYPR

Libmobi

by Bfabiszewski

Source repositories

CVEs (9)

  • CVE-2018-11726Jun 19, 2018
    risk 0.00cvss epss 0.01

    The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

  • CVE-2018-11725Jun 19, 2018
    risk 0.00cvss epss 0.01

    The mobi_parse_index_entry function in index.c in Libmobi 0.3 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted mobi file.

  • CVE-2018-11432May 30, 2018
    risk 0.00cvss epss 0.00

    The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

  • CVE-2018-11437May 30, 2018
    risk 0.00cvss epss 0.00

    The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.

  • CVE-2018-11436May 30, 2018
    risk 0.00cvss epss 0.00

    The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

  • CVE-2018-11438May 30, 2018
    risk 0.00cvss epss 0.02

    The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution (heap-based buffer overflow) via a crafted mobi file.

  • CVE-2018-11435May 30, 2018
    risk 0.00cvss epss 0.00

    The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.

  • CVE-2018-11434May 30, 2018
    risk 0.00cvss epss 0.00

    The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

  • CVE-2018-11433May 30, 2018
    risk 0.00cvss epss 0.00

    The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.