Vulnerabilities > Libxls Project

DATE CVE VULNERABILITY TITLE RISK
2018-12-25 CVE-2018-20450 Double Free vulnerability in Libxls Project Libxls 1.4.0
The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2017-2897.
network
low complexity
libxls-project CWE-415
6.5
2018-04-24 CVE-2017-12109 Integer Overflow or Wraparound vulnerability in Libxls Project Libxls 1.4
An exploitable integer overflow vulnerability exists in the xls_preparseWorkSheet function of libxls 1.4 when handling a MULRK record.
network
low complexity
libxls-project CWE-190
8.8
2018-04-24 CVE-2017-12108 Integer Overflow or Wraparound vulnerability in Libxls Project Libxls 1.4
An exploitable integer overflow vulnerability exists in the xls_preparseWorkSheet function of libxls 1.4 when handling a MULBLANK record.
network
low complexity
libxls-project CWE-190
8.8
2017-11-20 CVE-2017-2919 Out-of-bounds Write vulnerability in multiple products
An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4.
local
low complexity
libxls-project debian CWE-787
7.8
2017-11-20 CVE-2017-2897 Out-of-bounds Write vulnerability in Libxls Project Libxls 1.4.0
An exploitable out-of-bounds write vulnerability exists in the read_MSAT function of libxls 1.4.
local
low complexity
libxls-project CWE-787
7.8
2017-11-20 CVE-2017-2896 Out-of-bounds Write vulnerability in multiple products
An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4.
local
low complexity
libxls-project debian CWE-787
7.8
2017-11-20 CVE-2017-12111 Out-of-bounds Write vulnerability in Libxls Project Libxls 1.4
An exploitable out-of-bounds vulnerability exists in the xls_addCell function of libxls 1.4.
local
low complexity
libxls-project CWE-787
7.8
2017-11-20 CVE-2017-12110 Integer Overflow or Wraparound vulnerability in Libxls Project Libxls 1.4
An exploitable integer overflow vulnerability exists in the xls_appendSST function of libxls 1.4.A specially crafted XLS file can cause memory corruption resulting in remote code execution.
local
low complexity
libxls-project CWE-190
7.8