← Back

Librdf

librdf

5 CVEs • 2 products

Products (2)

Click to collapse
Toggle

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Librdf
1Raptor Rdf Syntax Library
Nov 3, 2025
Jan 10, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
1Librdf
1Raptor Rdf Syntax Library
Nov 3, 2025
Jan 10, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
3Debian
FedoraprojectLibrdf
3Debian Linux
FedoraRaptor Rdf Syntax Library
Nov 21, 2024
May 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
3Debian
FedoraprojectLibrdf
3Debian Linux
FedoraRaptor Rdf Syntax Library
Nov 21, 2024
Nov 6, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen i...Show more
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).Show less
6Apache
DebianFedoraproject+3 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+10 more
Apr 29, 2026
Jun 17, 2012
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via...Show more
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.Show less