Lucene search

K
cvelistMitreCVELIST:CVE-2018-19974
HistoryDec 17, 2018 - 6:00 p.m.

CVE-2018-19974

2018-12-1718:00:00
mitre
www.cve.org
5

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

45.7%

In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow attackers to discover addresses in the real stack (not the YARA virtual stack).

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

45.7%