VYPR

Libxls

by Libxls

Source repositories

CVEs (22)

  • CVE-2020-27819MedFeb 23, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when parsing XLS cells in libxls/xls2csv.c:199. It could allow a remote attacker to cause a denial of service via crafted XLS file.

  • CVE-2026-26825MedJun 3, 2026
    risk 0.34cvss 5.3epss 0.00

    A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with…

Page 2 of 2