CVE-2018-18059

MEDIUM

Bitdefender Scan Engines < 7.76675 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

An issue was discovered in Bitdefender Engines before 7.76675. A vulnerability has been discovered in the rar.xmd parser that results from a lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. Paired with other vulnerabilities, this can result in denial-of-service. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0033
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
bitdefender/scan_engines < 7.76675
Published May 24, 2019
Tracked Since Feb 18, 2026