VYPR
Vendor

Lief Project

Products
1
CVEs
11
Across products
11
Status
Private

Products

1

Recent CVEs

11
  • CVE-2021-32297HigSep 20, 2021
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an attacker to cause code Execution.

  • CVE-2022-38495HigSep 13, 2022
    risk 0.44cvss 7.8epss 0.00

    LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.

  • CVE-2022-38306HigSep 13, 2022
    risk 0.44cvss 7.8epss 0.00

    LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.

  • CVE-2022-43171MedNov 17, 2022
    risk 0.42cvss 6.5epss 0.01

    A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted MachO file.

  • CVE-2022-38496MedSep 13, 2022
    risk 0.36cvss 5.5epss 0.00

    LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.

  • CVE-2022-40922MedOct 3, 2022
    risk 0.35cvss 6.5epss 0.01

    A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file.

  • CVE-2022-40923MedSep 30, 2022
    risk 0.35cvss 6.5epss 0.01

    A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file.

  • CVE-2022-38497MedSep 13, 2022
    risk 0.29cvss 5.5epss 0.00

    LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.

  • CVE-2022-38307MedSep 13, 2022
    risk 0.29cvss 5.5epss 0.00

    LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO/SegmentCommand.cpp.

  • CVE-2024-31636LowMay 3, 2024
    risk 0.18cvss 3.9epss 0.00

    An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.

  • CVE-2025-15504LowJan 10, 2026
    risk 0.14cvss 3.3epss 0.00

    A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::parse_binary of the file src/ELF/Parser.tcc of the component ELF Binary Parser. The manipulation results in null pointer dereference. The attack must be…