libpff_project CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

libpff_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all libpff_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk buffer overflow and vendor risk memory corruption and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2020-18897 An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file. [email protected] 7.8 0.08% 2021-08-19 2024-11-21
CVE-2018-20348 libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite recursion) via a crafted file, related to libfdata_tree_get_node_value in libfdata_tree.c. [email protected] 5.5 0.06% 2018-12-22 2024-11-21
CVE-2018-11723 The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted pff file. NOTE: the vendor has disputed this as described in libyal/libpff issue 66 on GitHub [email protected] 5.5 0.14% 2018-06-19 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence