Lucene search

K
osvGoogleOSV:CVE-2018-19974
HistoryDec 17, 2018 - 7:29 p.m.

CVE-2018-19974

2018-12-1719:29:01
Google
osv.dev
8

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

45.7%

In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow attackers to discover addresses in the real stack (not the YARA virtual stack).

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

45.7%