← Back

Libpff Project

libpff_project

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Libpff
libpff

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libpff Project
1Libpff
Nov 21, 2024
Aug 19, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.
1Libpff Project
1Libpff
Nov 21, 2024
Dec 22, 2018
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite recursion) via a crafted file, related to libfdata_tree_get_node_value in...Show more
libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite recursion) via a crafted file, related to libfdata_tree_get_node_value in libfdata_tree.c.Show less
1Libpff Project
1Libpff
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted pff file...Show more
The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted pff file. NOTE: the vendor has disputed this as described in libyal/libpff issue 66 on GitHubShow less