{"id":"CVE-2018-5410","details":"Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver. An attacker can create a device handle to the system driver and send arbitrary input that will trigger the vulnerability. This vulnerability was introduced in the 1.0.0.5000 version update.","modified":"2026-07-08T19:45:45.855493Z","published":"2019-01-07T13:29:00.280Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106274"},{"type":"ADVISORY","url":"https://cwe.mitre.org/data/definitions/121.html"},{"type":"ADVISORY","url":"https://kb.cert.org/vuls/id/741315/"},{"type":"FIX","url":"https://github.com/dokan-dev/dokany/releases/tag/v1.2.1.1000"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/46155/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dokan-dev/dokany","events":[{"introduced":"0"},{"fixed":"f6de99b914b8f858acf940073ae8836eb476de7f"},{"fixed":"0134d391c9fe55ef2f0b990293e5b4c1e50e202a"}],"database_specific":{"cpe":"cpe:2.3:a:dokan-dev:dokany:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0.0.5000"},{"fixed":"1.2.0.1000"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.2.0.1000","v1.1.0.2000","v1.1.0","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0","v1.0.0-RC4","v1.0.0-RC3","v1.0.0-RC2","v1.0.0-RC1","v1.0.0-BETA1","v0.8.0","v0.8.0-RC4","v0.8.0-RC3","v0.7.4","v0.7.3-RC4","0.7.3-RC3","0.7.3-RC2","0.7.3-RC","0.7.3-beta","0.7.2","0.7.1","0.7.0","0.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-5410.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}