Out-of-bounds Read in the sendssifile function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12684.json"
"2026-04-11T12:27:29Z"
[
{
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/civetweb/civetweb/commit/8fd069f6dedb064339f1091069ac96f3f8bdb552",
"digest": {
"function_hash": "119767963597498349075607844267823066184",
"length": 1472.0
},
"id": "CVE-2018-12684-3d532852",
"deprecated": false,
"target": {
"file": "src/civetweb.c",
"function": "send_ssi_file"
}
},
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/civetweb/civetweb/commit/8fd069f6dedb064339f1091069ac96f3f8bdb552",
"digest": {
"threshold": 0.9,
"line_hashes": [
"172200892102564149905183411818307634882",
"72292759806246949969472507656980838155",
"235219493032028816082565176526409381387",
"256011461020833046236690677893975971495",
"286146812713583773153701970991195951009",
"100163630627650712582206041520738986959",
"275396511891190691215755055393810129830"
]
},
"id": "CVE-2018-12684-52dfee3c",
"deprecated": false,
"target": {
"file": "src/civetweb.c"
}
}
]