Lucene search

K
cvelistMitreCVELIST:CVE-2018-20340
HistoryMar 17, 2019 - 8:06 p.m.

CVE-2018-20340

2019-03-1720:06:42
mitre
www.cve.org
5

AI Score

7

Confidence

High

EPSS

0.002

Percentile

56.6%

Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.

AI Score

7

Confidence

High

EPSS

0.002

Percentile

56.6%