Vulnerabilities > Libxls Project > Libxls > High

DATE CVE VULNERABILITY TITLE RISK
2020-12-02 CVE-2017-2910 Out-of-bounds Write vulnerability in Libxls Project Libxls 2.0.0
An exploitable Out-of-bounds Write vulnerability exists in the xls_addCell function of libxls 2.0.
network
low complexity
libxls-project CWE-787
8.8
2018-12-25 CVE-2018-20452 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libxls Project Libxls 1.4.0
The read_MSAT_body function in ole.c in libxls 1.4.0 has an invalid free that allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, because of inconsistent memory management (new versus free) in ole2_read_header in ole.c.
network
low complexity
libxls-project CWE-119
8.8
2018-04-24 CVE-2017-12109 Integer Overflow or Wraparound vulnerability in Libxls Project Libxls 1.4
An exploitable integer overflow vulnerability exists in the xls_preparseWorkSheet function of libxls 1.4 when handling a MULRK record.
network
low complexity
libxls-project CWE-190
8.8
2018-04-24 CVE-2017-12108 Integer Overflow or Wraparound vulnerability in Libxls Project Libxls 1.4
An exploitable integer overflow vulnerability exists in the xls_preparseWorkSheet function of libxls 1.4 when handling a MULBLANK record.
network
low complexity
libxls-project CWE-190
8.8
2017-11-20 CVE-2017-2919 Out-of-bounds Write vulnerability in multiple products
An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4.
local
low complexity
libxls-project debian CWE-787
7.8
2017-11-20 CVE-2017-2897 Out-of-bounds Write vulnerability in Libxls Project Libxls 1.4.0
An exploitable out-of-bounds write vulnerability exists in the read_MSAT function of libxls 1.4.
local
low complexity
libxls-project CWE-787
7.8
2017-11-20 CVE-2017-2896 Out-of-bounds Write vulnerability in multiple products
An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4.
local
low complexity
libxls-project debian CWE-787
7.8
2017-11-20 CVE-2017-12111 Out-of-bounds Write vulnerability in Libxls Project Libxls 1.4
An exploitable out-of-bounds vulnerability exists in the xls_addCell function of libxls 1.4.
local
low complexity
libxls-project CWE-787
7.8
2017-11-20 CVE-2017-12110 Integer Overflow or Wraparound vulnerability in Libxls Project Libxls 1.4
An exploitable integer overflow vulnerability exists in the xls_appendSST function of libxls 1.4.A specially crafted XLS file can cause memory corruption resulting in remote code execution.
local
low complexity
libxls-project CWE-190
7.8