Lief Project
Products
1- 11 CVEs
Recent CVEs
11| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32297 | Hig | 0.50 | 8.8 | 0.02 | Sep 20, 2021 | An issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an attacker to cause code Execution. | ||
| CVE-2022-38495 | Hig | 0.44 | 7.8 | 0.00 | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c. | ||
| CVE-2022-38306 | Hig | 0.44 | 7.8 | 0.00 | Sep 13, 2022 | LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc. | ||
| CVE-2022-43171 | Med | 0.42 | 6.5 | 0.01 | Nov 17, 2022 | A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted MachO file. | ||
| CVE-2022-38496 | Med | 0.36 | 5.5 | 0.00 | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp. | ||
| CVE-2022-40922 | Med | 0.35 | 6.5 | 0.01 | Oct 3, 2022 | A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file. | ||
| CVE-2022-40923 | Med | 0.35 | 6.5 | 0.01 | Sep 30, 2022 | A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file. | ||
| CVE-2022-38497 | Med | 0.29 | 5.5 | 0.00 | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69. | ||
| CVE-2022-38307 | Med | 0.29 | 5.5 | 0.00 | Sep 13, 2022 | LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO/SegmentCommand.cpp. | ||
| CVE-2024-31636 | Low | 0.18 | 3.9 | 0.00 | May 3, 2024 | An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component. | ||
| CVE-2025-15504 | Low | 0.14 | 3.3 | 0.00 | Jan 10, 2026 | A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::parse_binary of the file src/ELF/Parser.tcc of the component ELF Binary Parser. The manipulation results in null pointer dereference. The attack must be… |
- risk 0.50cvss 8.8epss 0.02
An issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an attacker to cause code Execution.
- risk 0.44cvss 7.8epss 0.00
LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.
- risk 0.44cvss 7.8epss 0.00
LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.
- risk 0.42cvss 6.5epss 0.01
A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted MachO file.
- risk 0.36cvss 5.5epss 0.00
LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.
- risk 0.35cvss 6.5epss 0.01
A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file.
- risk 0.35cvss 6.5epss 0.01
A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file.
- risk 0.29cvss 5.5epss 0.00
LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.
- risk 0.29cvss 5.5epss 0.00
LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO/SegmentCommand.cpp.
- risk 0.18cvss 3.9epss 0.00
An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.
- risk 0.14cvss 3.3epss 0.00
A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::parse_binary of the file src/ELF/Parser.tcc of the component ELF Binary Parser. The manipulation results in null pointer dereference. The attack must be…