{"id":"CVE-2021-3888","details":"libmobi is vulnerable to Use of Out-of-range Pointer Offset","modified":"2026-07-08T12:40:59.675055Z","published":"2021-10-19T13:15:11.927Z","references":[{"type":"FIX","url":"https://github.com/bfabiszewski/libmobi/commit/c78e186739b50d156cb3da5d08d70294f0490853"},{"type":"FIX","url":"https://huntr.dev/bounties/722b3acb-792b-4429-a98d-bb80efb8938d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bfabiszewski/libmobi","events":[{"introduced":"0"},{"fixed":"40c21718a30e01ddffe4a16b6cbb2651d701d4ae"},{"fixed":"c78e186739b50d156cb3da5d08d70294f0490853"}],"database_specific":{"cpe":"cpe:2.3:a:libmobi_project:libmobi:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.8"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.7","v0.6","v0.5","v0.4","v0.3","v0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3888.json","vanir_signatures_modified":"2026-07-08T12:40:59Z","vanir_signatures":[{"target":{"file":"src/read.c"},"deprecated":false,"digest":{"line_hashes":["159374306872079646097456153994653664311","2889248071603708294494071628232096002","75372525134847231269862673464474276074","54339760918514445015195324222774347134"],"threshold":0.9},"id":"CVE-2021-3888-1cbcfef0","signature_type":"Line","signature_version":"v1","source":"https://github.com/bfabiszewski/libmobi/commit/c78e186739b50d156cb3da5d08d70294f0490853"},{"target":{"file":"src/read.c","function":"mobi_parse_huffdic"},"deprecated":false,"digest":{"function_hash":"120454384590572294039099634957026075624","length":1456},"id":"CVE-2021-3888-2bd91934","signature_type":"Function","signature_version":"v1","source":"https://github.com/bfabiszewski/libmobi/commit/c78e186739b50d156cb3da5d08d70294f0490853"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"}]}