Vulnerabilities > Virustotal > Yara > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-28 | CVE-2023-40857 | Out-of-bounds Write vulnerability in Virustotal Yara 4.3.2 Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component. | 8.8 |
2019-12-09 | CVE-2019-19648 | Out-of-bounds Read vulnerability in multiple products In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. | 7.8 |
2018-06-15 | CVE-2018-12035 | Out-of-bounds Write vulnerability in Virustotal Yara In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability in yr_execute_code in libyara/exec.c. | 7.8 |
2018-06-15 | CVE-2018-12034 | Out-of-bounds Read vulnerability in Virustotal Yara In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/exec.c. | 7.8 |
2017-06-06 | CVE-2017-9465 | Out-of-bounds Read vulnerability in Virustotal Yara 3.6.1 The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c. | 7.1 |
2017-06-05 | CVE-2017-9438 | Uncontrolled Recursion vulnerability in Virustotal Yara 3.5.0 libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_emit function, a different vulnerability than CVE-2017-9304. | 7.5 |
2017-05-31 | CVE-2017-9304 | Uncontrolled Recursion vulnerability in Virustotal Yara 3.5.0 libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit function. | 7.5 |
2017-05-14 | CVE-2017-8929 | Use After Free vulnerability in Virustotal Yara 3.5.0 The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule. | 7.5 |
2017-04-27 | CVE-2017-8294 | Out-of-bounds Read vulnerability in Virustotal Yara 3.5.0 libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function. | 7.5 |
2017-04-03 | CVE-2017-5924 | Use After Free vulnerability in Virustotal Yara 3.5.0 libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_compiler_destroy function. | 7.5 |