Halibut Project Halibut vulnerabilities
4 known vulnerabilities affecting halibut_project/halibut.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3
Vulnerabilities
Page 1 of 1
CVE-2021-42612HIGHCVSS 7.8v1.22022-05-24
CVE-2021-42612 [HIGH] CWE-416 CVE-2021-42612: A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentati
A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.
nvdosv
CVE-2021-42613HIGHCVSS 7.8v1.22022-05-24
CVE-2021-42613 [HIGH] CWE-415 CVE-2021-42613: A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of ser
A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.
nvdosv
CVE-2021-42614HIGHCVSS 7.8v1.22022-05-24
CVE-2021-42614 [HIGH] CWE-416 CVE-2021-42614: A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a se
A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have unspecified other impact via a crafted text document.
nvdosv
CVE-2021-31819CRITICAL≥ 0, < 4.4.72021-09-23
CVE-2021-31819 [CRITICAL] CWE-502 Remote Code Execution in Halibut
Remote Code Execution in Halibut
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.
ghsaosv