Lucene search

K

Freexl Project Security Vulnerabilities

cve
cve

CVE-2017-2923

An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.

8.8CVSS

9AI Score

0.021EPSS

2018-04-24 07:29 PM
54
2
cve
cve

CVE-2017-2924

An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.

8.8CVSS

9AI Score

0.021EPSS

2018-04-24 07:29 PM
63
4
cve
cve

CVE-2018-7435

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function.

8.8CVSS

8.5AI Score

0.005EPSS

2018-02-23 09:29 PM
52
cve
cve

CVE-2018-7436

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.

8.8CVSS

8.5AI Score

0.005EPSS

2018-02-23 09:29 PM
50
cve
cve

CVE-2018-7437

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function.

8.8CVSS

8.5AI Score

0.005EPSS

2018-02-23 09:29 PM
59
cve
cve

CVE-2018-7438

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string function.

8.8CVSS

8.5AI Score

0.005EPSS

2018-02-23 09:29 PM
52
cve
cve

CVE-2018-7439

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record.

8.8CVSS

8.5AI Score

0.005EPSS

2018-02-23 09:29 PM
45