Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-19975

In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_COUNT can read a DWORD.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.3%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 7.1
Products affected by CVE-2018-19975
  • Virustotal » Yara » Version: 3.8.1
    cpe:2.3:a:virustotal:yara:3.8.1


Contact Us

Shodan ® - All rights reserved