Vulnerabilities > File Project

DATE CVE VULNERABILITY TITLE RISK
2023-08-22 CVE-2022-48554 Out-of-bounds Read vulnerability in multiple products
File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c.
local
low complexity
file-project debian CWE-125
5.5
2019-10-21 CVE-2019-18218 Out-of-bounds Write vulnerability in multiple products
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
7.8
2019-02-18 CVE-2019-8907 Out-of-bounds Write vulnerability in multiple products
do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
network
low complexity
file-project debian opensuse canonical CWE-787
8.8
2019-02-18 CVE-2019-8906 Out-of-bounds Read vulnerability in multiple products
do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
4.4
2019-02-18 CVE-2019-8905 Out-of-bounds Read vulnerability in multiple products
do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.
4.4
2019-02-18 CVE-2019-8904 Out-of-bounds Read vulnerability in multiple products
do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.
network
low complexity
file-project canonical CWE-125
8.8
2018-06-11 CVE-2018-10360 Out-of-bounds Read vulnerability in multiple products
The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
network
low complexity
file-project canonical opensuse CWE-125
6.5
2017-09-11 CVE-2017-1000249 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in File Project File 5.29
An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary.
local
low complexity
file-project CWE-119
5.5