Show plain JSON{"id": "CVE-2018-18058", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 2.6, "accessVector": "NETWORK", "vectorString": "AV:N/AC:H/Au:N/C:N/I:N/A:P", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "HIGH", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 4.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "REQUIRED", "attackComplexity": "HIGH", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 1.6}]}, "published": "2019-05-24T17:29:02.087", "references": [{"url": "https://www.bitdefender.com/", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.bitdefender.com/support/security-advisories/bitdefender-iso-xmd-iso-parsing-bounds-read-vulnerability/", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.bitdefender.com/", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.bitdefender.com/support/security-advisories/bitdefender-iso-xmd-iso-parsing-bounds-read-vulnerability/", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-369"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in Bitdefender Engines before 7.76662. A vulnerability has been discovered in the iso.xmd parser that results from a lack of proper validation of user-supplied data, which can result in a division-by-zero circumstance. Paired with other vulnerabilities, this can result in denial-of-service. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file."}, {"lang": "es", "value": "Fue encontrado un problema en Bitdefender Engines en versiones anteriores a la 7.76662. Se ha descubierto una vulnerabilidad en el analizador iso.xmd que resulta de una falta de comprobaci\u00f3n adecuada de los datos suministrados por el usuario, lo que puede conllevar a una circunstancia de divisi\u00f3n por cero. Junto con otras vulnerabilidades, esto resultar\u00eda en una Denegaci\u00f3n de Servicios (DoS). La interacci\u00f3n del usuario es necesaria para explotar esta vulnerabilidad, ya que la v\u00edctima debe visitar una p\u00e1gina maliciosa o abrir un archivo malicioso."}], "lastModified": "2024-11-21T03:55:24.470", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:bitdefender:scan_engines:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9D0E1E5-A55D-4C2D-9550-22A5E1C13013", "versionEndExcluding": "7.76662"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}