CVE-2018-11432 describes a heap-based buffer over-read vulnerability in the mobi_parse_mobiheader function of Libmobi 0.3, affecting libmobi_project libmobi. This medium-severity flaw (CVSS 6.5) can lead to information disclosure if a user opens a specially crafted mobi file. While no public exploits, Metasploit modules, or Nuclei templates are available, and there's minimal community discussion or media coverage, the vulnerability could still be leveraged for data exfiltration. There is no evidence of active exploitation or inclusion in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.3CPE matchmatch criteria | cpe:2.3:a:libmobi_project:libmobi:0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.