Known Vulnerabilities for products from Htslib
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Htslib".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-36403 json | HTSlib 1.10 through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read). | 8.8 - HIGH | 2021-07-01 | 2023-02-03 |
| CVE-2018-14329 json | In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack. | 4.7 - MEDIUM | 2018-07-17 | 2019-09-18 |
| CVE-2018-13845 json | An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c. | 9.8 - CRITICAL | 2018-07-10 | 2019-10-03 |
| CVE-2018-13844 json | ** DISPUTED ** An issue has been found in HTSlib 1.8. It is a memory leak in fai_read in faidx.c. NOTE: This has been dispute... | 7.5 - HIGH | 2018-07-10 | 2023-11-07 |
| CVE-2018-13843 json | ** DISPUTED ** An issue has been found in HTSlib 1.8. It is a memory leak in bgzf_getline in bgzf.c. NOTE: the software maint... | 7.5 - HIGH | 2018-07-10 | 2023-11-07 |
| CVE-2017-1000206 json | samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potent... | Not Provided | 2017-11-17 | 2025-04-20 |
Known software with vulnerabilities from Htslib
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Htslib | Htslib | 0.2.0 |