Vulnerabilities > Virustotal > Yara > High

DATE CVE VULNERABILITY TITLE RISK
2023-08-28 CVE-2023-40857 Out-of-bounds Write vulnerability in Virustotal Yara 4.3.2
Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component.
network
low complexity
virustotal CWE-787
8.8
2019-12-09 CVE-2019-19648 Out-of-bounds Read vulnerability in multiple products
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size.
local
low complexity
virustotal fedoraproject CWE-125
7.8
2017-06-05 CVE-2017-9438 Uncontrolled Recursion vulnerability in Virustotal Yara 3.5.0
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_emit function, a different vulnerability than CVE-2017-9304.
network
low complexity
virustotal CWE-674
7.5