Discount Project maintains a markdown-parsing library that, despite a narrow product scope, achieves significant adoption across documentation and content-rendering systems where memory-safety handling is critical. The observed vulnerability pattern centers on out-of-bounds read conditions, a class endemic to string and buffer processing in C-based parsers, and current severity and exploitation data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Discount Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12495MEDIUM The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file. | Jun 15, 2018 | 5.5 | 19 | NO | NO |
CVE-2018-11504MEDIUM The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demo | May 26, 2018 | 5.5 | 19 | NO | NO |
CVE-2018-11503MEDIUM The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as | May 26, 2018 | 5.5 | 19 | NO | NO |
CVE-2018-11468MEDIUM The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, a | May 25, 2018 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Discount Project.
Media articles that mention a CVE ID that affects a product developed by Discount Project — matched by CVE ID, not by vendor name.