{"id":"CVE-2018-12086","details":"Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.","aliases":["GHSA-782p-53wq-cxmj"],"modified":"2026-05-18T05:51:26.662597698Z","published":"2018-09-14T21:29:03.583Z","related":["SUSE-SU-2018:3282-1","SUSE-SU-2018:3590-1","SUSE-SU-2018:3590-2","SUSE-SU-2018:3590-3","SUSE-SU-2020:0693-1","openSUSE-SU-2020:0362-1","openSUSE-SU-2024:11513-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"9.0"}],"cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"vendor_product":"debian:debian_linux","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"1.03.342"}],"cpes":["cpe:2.3:a:opcfoundation:unified_architecture-.net-legacy:*:*:*:*:*:*:*:*"],"vendor_product":"opcfoundation:unified_architecture-.net-legacy","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"1.03.343"}],"cpes":["cpe:2.3:a:opcfoundation:unified_architecture-java:*:*:*:*:*:*:*:*"],"vendor_product":"opcfoundation:unified_architecture-java","source":"CPE_FIELD"}]},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/105538"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1041909"},{"type":"ADVISORY","url":"https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2018-12086.pdf"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4359"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/OPCF-Members/UA-.NET-Legacy","events":[{"introduced":"0"},{"last_affected":"fedc75497a3d83529da3a3ca65ce0bd1661ff4bb"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.03.340"}],"cpe":"cpe:2.3:a:opcfoundation:unified_architecture_ansic:*:*:*:*:*:*:*:*","source":"CPE_FIELD"}}],"versions":["1.03.340","1.02.336"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-12086.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/opcfoundation/ua-.netstandard","events":[{"introduced":"0"},{"last_affected":"ea4f128d7fc8738e05cd9586d5126284a621f622"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.03.352.12"}],"cpe":"cpe:2.3:a:opcfoundation:unified_architecture_.net-standard:*:*:*:*:*:*:*:*","source":"CPE_FIELD"}}],"versions":["1.03.352.12","1.03.352.10","1.03.351.7","1.03.350.6","1.03.350"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-12086.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}