CVE-2018-11724: Libmobi Project Libmobi

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

The mobi_pk1_decrypt function in encryption.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

Affected products

Published 2018-06-19. Last modified 2026-06-17.