Freexl Project Freexl vulnerabilities
10 known vulnerabilities affecting freexl_project/freexl.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2017-2924P3HIGHCVSS 8.8v1.0.32018-04-24
CVE-2017-2924 [HIGH] CWE-787 CVE-2017-2924: An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of F
An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
nvdosv
CVE-2017-2923P3HIGHCVSS 8.8v1.0.32018-04-24
CVE-2017-2923 [HIGH] CWE-787 CVE-2017-2923: An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record functio
An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
nvdosv
CVE-2018-7436P3HIGHCVSS 8.8fixed in 1.0.52018-02-23
CVE-2018-7436 [HIGH] CWE-125 CVE-2018-7436: An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.
nvdosv
CVE-2018-7439P4HIGHCVSS 8.8fixed in 1.0.52018-02-23
CVE-2018-7439 [HIGH] CWE-125 CVE-2018-7439: An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the functi
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record.
nvdosv
CVE-2018-7435P4HIGHCVSS 8.8fixed in 1.0.52018-02-23
CVE-2018-7435 [HIGH] CWE-125 CVE-2018-7435: An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function.
nvdosv
CVE-2015-2753P4MEDIUMCVSS 6.8≥ 0, < 1.0.0g-1+deb8u12015-03-31
CVE-2015-2753 [MEDIUM] CVE-2015-2753: FreeXL before 1
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector in a workbook.
osv
CVE-2015-2754P4MEDIUMCVSS 6.8≥ 0, < 1.0.0g-1+deb8u12015-03-31
CVE-2015-2754 [MEDIUM] CVE-2015-2754: FreeXL before 1
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitrary code via a crafted workbook, related to a "premature EOF."
osv
CVE-2018-7438P4HIGHCVSS 8.8fixed in 1.0.52018-02-23
CVE-2018-7438 [HIGH] CWE-125 CVE-2018-7438: An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string function.
nvdosv
CVE-2018-7437P4HIGHCVSS 8.8fixed in 1.0.52018-02-23
CVE-2018-7437 [HIGH] CWE-125 CVE-2018-7437: An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy c
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function.
nvdosv
CVE-2015-2776P4MEDIUMCVSS 4.3≥ 0, < 1.0.0g-1+deb8u12015-03-31
CVE-2015-2776 [MEDIUM] CVE-2015-2776: The parse_SST function in FreeXL before 1
The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook.
osv