Libmobi

Vendor:

First CVE: May 30, 2018 · Active for 8 years

21
Total CVEs
More Total CVEs than 94% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libmobi over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 30, 2018
8 years ago
Most Recent CVE
Jul 1, 2022
1,484 days ago

CVE Severity & Scoring

Libmobi21 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local3 (14.3%)
Network18 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (19.0%)
Unknown0 (0.0%)
Required17 (81.0%)
Privileges Required
Low2 (9.5%)
High0 (0.0%)
None19 (90.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
libmobi is vulnerable to Out-of-bounds Write
Sep 15, 20219.832NONO
libmobi is vulnerable to Out-of-bounds Read
Oct 15, 20219.831NONO
libmobi is vulnerable to Use of Out-of-range Pointer Offset
Oct 19, 20218.126NONO
libmobi is vulnerable to Use of Out-of-range Pointer Offset
Oct 19, 20218.126NONO
The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other
Jun 19, 20188.826NONO
The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution (heap-based buffer overflow) via a crafted mobi file.
May 30, 20188.826NONO
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary code execution.
Apr 29, 20227.825NONO
The mobi_pk1_decrypt function in encryption.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other im
Jun 19, 20188.825NONO
libmobi before v0.10 contains a NULL pointer dereference via the component mobi_buffer_getpointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craf
Jun 2, 20226.522NONO
NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11.
Jul 1, 20225.521NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Libmobi

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.3107.21.8%00