← Vulnerability feed

Vulnerability record · CVE-2018-7485 · published 26 February 2018

CVE-2018-7485: Unixodbc memory buffer overflow vulnerability

Unixodbc · Unixodbc

The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.

9.8 CVSS 3.0 Critical EPSS 3.0% · top 13.0% CWE-119 · Memory buffer overflow
9.8CVSS 3.0 base score, v2 7.5
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-7485 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-7409Unixodbc memory buffer overflow vulnerabilityIn unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.EPSS 2.5%7.8CVE-2024-1013Unixodbc vulnerabilityAn out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue ma…EPSS 0.28%7.8CVE-2011-1145Unixodbc classic buffer overflow vulnerabilityThe SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE para…EPSS 0.45%2.1CVE-2012-2658Unixodbc memory buffer overflow vulnerabilityBuffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (crash) via a long string in the D…EPSS 0.51%2.1CVE-2012-2657Unixodbc memory buffer overflow vulnerabilityBuffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a…EPSS 0.44%8.7CVE-2026-88779Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and befor…KEVEPSS 0.53%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEVEPSS 1.3%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2018-7485), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.