CVE-2018-12034: Virustotal Yara

High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.

In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/exec.c.

Affected products

Published 2018-06-15. Last modified 2026-06-17.