plusvic

2 exploits Active since Apr 2017
CVE-2017-5923 WRITEUP HIGH WRITEUP
YARA 3.5.0 - Denial of Service via Crafted Rule in yara_yyparse Function
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted rule that is mishandled in the yara_yyparse function.
CVSS 7.5
CVE-2017-5924 WRITEUP HIGH WRITEUP
YARA 3.5.0 - Use-After-Free in Grammar Parser
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_compiler_destroy function.
CVSS 7.5