libmobi_project 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
一般的な弱点パターンには バッファオーバーフロー、vendor risk memory corruption, and パス処理の欠陥 があり、vendor surface production workloads and vendor surface software deployment の利用場面で アプリケーションクラッシュ、vendor impact memory corruption, and ファイル上書き などのリスクが生じる可能性があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2022-2279 | NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11. | [email protected] | 5.5 | 0.53% | 2022-07-01 | 2024-11-21 |
| CVE-2022-1987 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. | [email protected] | 8.1 | 0.77% | 2022-06-03 | 2024-11-21 |
| CVE-2022-29788 | libmobi before v0.10 contains a NULL pointer dereference via the component mobi_buffer_getpointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mobi file. | [email protected] | 6.5 | 0.78% | 2022-06-02 | 2024-11-21 |
| CVE-2022-1908 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. | [email protected] | 8.1 | 0.67% | 2022-05-27 | 2024-11-21 |
| CVE-2022-1907 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. | [email protected] | 8.1 | 0.66% | 2022-05-27 | 2024-11-21 |
| CVE-2022-1534 | Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. | [email protected] | 7.1 | 0.34% | 2022-04-29 | 2024-11-21 |
| CVE-2022-1533 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary code execution. | [email protected] | 7.8 | 0.40% | 2022-04-29 | 2024-11-21 |
| CVE-2021-3889 | libmobi is vulnerable to Use of Out-of-range Pointer Offset | [email protected] | 8.1 | 1.20% | 2021-10-19 | 2024-11-21 |
| CVE-2021-3888 | libmobi is vulnerable to Use of Out-of-range Pointer Offset | [email protected] | 8.1 | 1.20% | 2021-10-19 | 2024-11-21 |
| CVE-2021-3881 | libmobi is vulnerable to Out-of-bounds Read | [email protected] | 9.8 | 1.12% | 2021-10-15 | 2024-11-21 |
| CVE-2021-3751 | libmobi is vulnerable to Out-of-bounds Write | [email protected] | 9.8 | 1.20% | 2021-09-15 | 2024-11-21 |
| CVE-2018-11726 | The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file. | [email protected] | 8.8 | 2.55% | 2018-06-19 | 2024-11-21 |
| CVE-2018-11725 | The mobi_parse_index_entry function in index.c in Libmobi 0.3 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted mobi file. | [email protected] | 6.5 | 2.54% | 2018-06-19 | 2024-11-21 |
| CVE-2018-11724 | The mobi_pk1_decrypt function in encryption.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file. | [email protected] | 8.8 | 1.55% | 2018-06-19 | 2024-11-21 |
| CVE-2018-11438 | The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution (heap-based buffer overflow) via a crafted mobi file. | [email protected] | 8.8 | 2.67% | 2018-05-30 | 2024-11-21 |
| CVE-2018-11437 | The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file. | [email protected] | 6.5 | 1.43% | 2018-05-30 | 2024-11-21 |
| CVE-2018-11436 | The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file. | [email protected] | 6.5 | 1.43% | 2018-05-30 | 2024-11-21 |
| CVE-2018-11435 | The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file. | [email protected] | 6.5 | 1.44% | 2018-05-30 | 2024-11-21 |
| CVE-2018-11434 | The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file. | [email protected] | 6.5 | 1.43% | 2018-05-30 | 2024-11-21 |
| CVE-2018-11433 | The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file. | [email protected] | 6.5 | 1.43% | 2018-05-30 | 2024-11-21 |