CVE-2018-12648 describes a NULL pointer dereference vulnerability in the WEBP::GetLE32 function within XMPFiles/source/FormatSupport/WEBP_Support.hpp of Exempi 2.4.5. This flaw, rated with a CVSS score of 7.5 (HIGH), allows for a denial-of-service attack with low attack complexity and no user interaction required, impacting the availability of affected systems. Despite its high severity, there is currently no evidence of active exploitation, nor is exploit code available on platforms like Metasploit, Nuclei, or ExploitDB. Furthermore, the vulnerability has garnered minimal community discussion and media coverage, suggesting a low profile in the threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.5CPE matchmatch criteria | cpe:2.3:a:exempi_project:exempi:2.4.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.