Libmobi ProjectCVEs & Vulnerabilities

21 CVEs affecting Libmobi Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

libmobi 21
CVE-2022-2279MEDIUM

NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11.

1 Jul 2022
5.5
CVSS
CVE-2022-1987HIGH

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

3 Jun 2022
8.1
CVSS
CVE-2022-29788MEDIUM

libmobi before v0.10 contains a NULL pointer dereference via the component mobi_buffer_getpointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mobi file.

2 Jun 2022
6.5
CVSS
CVE-2022-1908HIGH

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

27 May 2022
8.1
CVSS
CVE-2022-1907HIGH

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

27 May 2022
8.1
CVSS
CVE-2022-1534HIGH

Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

29 Apr 2022
7.1
CVSS
CVE-2022-1533HIGH

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary code execution.

29 Apr 2022
7.8
CVSS
CVE-2021-3889HIGH

libmobi is vulnerable to Use of Out-of-range Pointer Offset

19 Oct 2021
8.1
CVSS
CVE-2021-3888HIGH

libmobi is vulnerable to Use of Out-of-range Pointer Offset

19 Oct 2021
8.1
CVSS
CVE-2021-3881CRITICAL

libmobi is vulnerable to Out-of-bounds Read

15 Oct 2021
9.8
CVSS
CVE-2021-3751CRITICAL

libmobi is vulnerable to Out-of-bounds Write

15 Sep 2021
9.8
CVSS
CVE-2018-11726HIGH

The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

20 Jun 2018
8.8
CVSS
CVE-2018-11725MEDIUM

The mobi_parse_index_entry function in index.c in Libmobi 0.3 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted mobi file.

20 Jun 2018
6.5
CVSS
CVE-2018-11724HIGH

The mobi_pk1_decrypt function in encryption.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

20 Jun 2018
8.8
CVSS
CVE-2018-11438HIGH

The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution (heap-based buffer overflow) via a crafted mobi file.

30 May 2018
8.8
CVSS
CVE-2018-11437MEDIUM

The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.

30 May 2018
6.5
CVSS
CVE-2018-11436MEDIUM

The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

30 May 2018
6.5
CVSS
CVE-2018-11435MEDIUM

The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.

30 May 2018
6.5
CVSS
CVE-2018-11434MEDIUM

The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

30 May 2018
6.5
CVSS
CVE-2018-11433MEDIUM

The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

30 May 2018
6.5
CVSS
CVE-2018-11432MEDIUM

The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

30 May 2018
6.5
CVSS
← PrevPage 1 / 1Next →
Libmobi Project CVEs & Vulnerabilities — 21 Tracked