Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yara HIGH 8.8
CVE-2023-40857

Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the ex…

No fix yet
Fix from $1,950 2023-08-28
Yara MEDIUM 5.5
CVE-2021-45429

A Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yr_set_configuration in yara/libyar…

Fix: after 4.1.3
Fix from $1,600 2022-02-04
Yara MEDIUM 5.5
CVE-2019-5020

An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a n…

No fix yet
Fix from $1,600 2019-07-31
Yara MEDIUM 5.5
CVE-2018-19976

In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequenc…

No fix yet
Fix from $1,600 2018-12-17
Yara MEDIUM 5.5
CVE-2018-19974

In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow att…

No fix yet
Fix from $1,600 2018-12-17
Yara MEDIUM 5.5
CVE-2018-19975

In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_…

No fix yet
Fix from $1,600 2018-12-17
Yara HIGH 7.8
CVE-2018-12034

In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/e…

Fix: after 3.7.1
Fix from $1,950 2018-06-15
Yara HIGH 7.8
CVE-2018-12035

In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability in yr_execute_code in libyara/…

Fix: after 3.7.1
Fix from $1,950 2018-06-15
Virustotal HIGH 7.8
CVE-2018-10408

An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full i…

No fix yet
Fix from $1,950 2018-06-13
Yara MEDIUM 5.5
CVE-2017-11328

Heap buffer overflow in the yr_object_array_set_item() function in object.c in YARA 3.x allows a denial-of-service attack by scanning a crafted .NET …

Patch available
Fix from $1,600 2017-07-17
Yara HIGH 7.1
CVE-2017-9465

The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtai…

Patch available
Fix from $1,950 2017-06-06
Yara HIGH 7.5
CVE-2017-9438

libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involvin…

Patch available
Fix from $1,950 2017-06-05
Yara HIGH 7.5
CVE-2017-9304

libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is m…

Patch available
Fix from $1,950 2017-05-31
Yara HIGH 7.5
CVE-2017-8929

The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and applicatio…

Patch available
Fix from $1,950 2017-05-14
Yara HIGH 7.5
CVE-2017-8294

libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via…

Patch available
Fix from $1,950 2017-04-27
Yara HIGH 7.5
CVE-2016-10210

libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rul…

Patch available
Fix from $1,950 2017-04-03
Yara HIGH 7.5
CVE-2016-10211

libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that i…

Patch available
Fix from $1,950 2017-04-03
Yara HIGH 7.5
CVE-2017-5923

libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a craf…

Patch available
Fix from $1,950 2017-04-03
Yara HIGH 7.5
CVE-2017-5924

libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that i…

Patch available
Fix from $1,950 2017-04-03