CVE-2018-18060
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Bitdefender Engines before 7.76808. A vulnerability has been discovered in the dalvik.xmd parser that results from a lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. Paired with other vulnerabilities, this can result in denial-of-service. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Fue encontrado un problema en Bitdefender Engines en versiones anteriores a la 7.76808. Una vulnerabilidad ha sido encontrada en el analizador dalvik.xmd que resulta de una falta de comprobación adecuada de los datos suministrados por el usuario, lo que puede conllevar a una lectura después del final de un búfer asignado. Junto con otras vulnerabilidades, esto resultaría en una Denegación de Servicios (DoS). La interacción del usuario es necesaria para explotar esta vulnerabilidad, ya que la víctima debe visitar una página maliciosa o abrir un archivo malicioso.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-10-08 CVE Reserved
- 2019-05-24 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.bitdefender.com | 2019-05-29 | |
https://www.bitdefender.com/support/security-advisories/bitdefender-dalvik-xmd-apk-parsing-bounds-read-vulnerability | 2019-05-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bitdefender Search vendor "Bitdefender" | Scan Engines Search vendor "Bitdefender" for product "Scan Engines" | < 7.76808 Search vendor "Bitdefender" for product "Scan Engines" and version " < 7.76808" | - |
Affected
|