CVE-2020-36403
- EPSS 0.45%
- Veröffentlicht 01.07.2021 03:15:07
- Zuletzt bearbeitet 21.11.2024 05:29:25
HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).
CVE-2018-14329
- EPSS 0.04%
- Veröffentlicht 17.07.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:49
In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.
CVE-2018-13843
- EPSS 0.37%
- Veröffentlicht 10.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:10
An issue has been found in HTSlib 1.8. It is a memory leak in bgzf_getline in bgzf.c. NOTE: the software maintainer's position is that the "failure to free memory" can be fixed in applications that use the HTSlib library (such as test/test_bgzf.c in ...
CVE-2018-13844
- EPSS 0.37%
- Veröffentlicht 10.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:10
An issue has been found in HTSlib 1.8. It is a memory leak in fai_read in faidx.c. NOTE: This has been disputed with the assertion that this vulnerability exists in the test harness and HTSlib users would be aware of the need to destruct this object ...
CVE-2018-13845
- EPSS 0.43%
- Veröffentlicht 10.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:10
An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c.
CVE-2017-1000206
- EPSS 0.63%
- Veröffentlicht 17.11.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution