ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-18584
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading

In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.

NVD description · AI analysis pending
6.53%
  • cabextract project cabextract
  • cabextract project libmspack
  • cabextract project debian linux
  • +1 more
CVE-2018-14682
+3 in the same advisory: …14681 …14680 …14679
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha.

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.

NVD description · AI analysis pending
8.8
group max
4%
  • cabextract libmspack
  • cabextract cabextract
  • cabextract ubuntu linux
  • +1 more