CVE-2018-12034: Virustotal Yara
High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.
In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/exec.c.
Affected products
- Virustotal Yara: up to and including 3.7.1
Published 2018-06-15. Last modified 2026-06-17.