VYPR

Libpff

by Libyal

Source repositories

CVEs (3)

  • CVE-2018-11723MedJun 19, 2018
    risk 0.36cvss 5.5epss 0.01

    The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted pff file. NOTE: the vendor has disputed this as described in…

  • CVE-2020-18897Aug 19, 2021
    risk 0.00cvss epss 0.01

    An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.

  • CVE-2018-20348Dec 22, 2018
    risk 0.00cvss epss 0.00

    libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite recursion) via a crafted file, related to libfdata_tree_get_node_value in libfdata_tree.c.