Vcftools is a specialized genomics and bioinformatics toolkit for filtering and processing VCF (Variant Call Format) files, a narrow but essential component in computational biology pipelines. The observed vulnerability signal centers on memory-safety issues within the toolkit, specifically use-after-free conditions and out-of-bounds reads that arise in the parser and data-handling layers; current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vcftools Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11130HIGH The header::add_FORMAT_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other | May 17, 2018 | 7.8 | 33 | NO | NO |
CVE-2019-1010127HIGH VCFTools vcftools prior to version 0.1.15 is affected by: Use-after-free. The impact is: Denial of Service or possibly other impact (eg. code execution or information disclosure). | Jul 25, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-11129HIGH The header::add_INFO_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other i | May 17, 2018 | 7.8 | 23 | NO | NO |
CVE-2018-11099MEDIUM The header::add_INFO_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted vcf fi | May 17, 2018 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vcftools Project.
Media articles that mention a CVE ID that affects a product developed by Vcftools Project — matched by CVE ID, not by vendor name.