VDB

CVE-2018-25153

CVE-2018-25153 REJECTED CVSS 6.900000095367432 MEDIUM

GNU Barcode 0.99 contains a memory leak vulnerability in the command line processing function within cmdline.c. Attackers can exploit this vulnerability by providing specially crafted input that causes unfreed memory allocations, potentially leading to denial of service conditions.

EPSS 0.03% · 7.2th percentile

Risk Scores

CVSS 4.0
6.900000095367432
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.03%
7.2th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSbarcode0.99-7, 0.99-6, 0
Ubuntu:18.04:LTSbarcode0, 0.98+debian-9.1build1, 0.98+debian-9.1
Ubuntu:25.10barcode0.99-9, 0
Ubuntu:25.04barcode0.99-8build1, 0.99-8, 0
Ubuntu:20.04:LTSbarcode0.99-3, 0
Ubuntu:16.04:LTSbarcode0, 0.98+debian-9.1
Ubuntu:22.04:LTSbarcode0.99-4, 0, 0.99-5

Timeline

  • Dec 24, 2025 CVE Published
  • Dec 25, 2025 EPSS Score
  • Dec 26, 2025 EPSS Score
  • Dec 26, 2025 PoC Published
  • Dec 26, 2025 PoC Published
  • Dec 26, 2025 CVE Updated
  • Dec 27, 2025 EPSS Score
  • Dec 28, 2025 EPSS Score
  • Dec 29, 2025 EPSS Score
  • Apr 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›