Thunlp develops a focused natural-language processing toolkit, THULAC, that provides text segmentation and part-of-speech tagging for Chinese language processing. Its reported vulnerabilities cluster around memory-safety issues, including improper bounds checking, NULL pointer dereference, and out-of-bounds reads, which are characteristic of native-code parsing and tokenization components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thunlp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14565CRITICAL An issue was discovered in libthulac.so in THULAC through 2018-02-25. A heap-based buffer over-read can occur in NGramFeature::find_bases in include/cb_ngram_feature.h. | Jul 23, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-14564CRITICAL An issue was discovered in libthulac.so in THULAC through 2018-02-25. A SEGV can occur in NGramFeature::find_bases in include/cb_ngram_feature.h. | Jul 23, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-14563CRITICAL An issue was discovered in libthulac.so in THULAC through 2018-02-25. "operator delete" is used with "operator new[]" in the TaggingLearner class in include/cb_tagging_learner.h, p | Jul 23, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-14562CRITICAL An issue was discovered in libthulac.so in THULAC through 2018-02-25. A NULL pointer dereference can occur in the BasicModel class in include/cb_model.h. | Jul 23, 2018 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thunlp.
Media articles that mention a CVE ID that affects a product developed by Thunlp — matched by CVE ID, not by vendor name.