VDB

CVE-2018-25154

CVE-2018-25154 PUBLISHED CVSS 9.800000190734863 CRITICAL

GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.

EPSS 0.38% · 31.1th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.38%
31.1th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSbarcode0.99-6, 0, 0.99-7
Ubuntu:25.10barcode0.99-9, 0
Ubuntu:22.04:LTSbarcode0, 0.99-5, 0.99-4
Ubuntu:16.04:LTSbarcode0.98+debian-9.1, 0
Ubuntu:20.04:LTSbarcode0, 0.99-3
Ubuntu:18.04:LTSbarcode0, *, *

Timeline

  • Dec 24, 2025 CVE Published
  • Dec 24, 2025 PoC Published
  • Dec 24, 2025 PoC Published
  • Dec 25, 2025 EPSS Score
  • Dec 29, 2025 EPSS Score
  • Jan 2, 2026 EPSS Score
  • Jan 6, 2026 EPSS Score
  • Jan 10, 2026 EPSS Score
  • Jan 14, 2026 EPSS Score
  • Jan 18, 2026 EPSS Score
  • Jan 22, 2026 EPSS Score
  • Jan 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›