cbcvebase.

Gnu Libextractor vulnerabilities

29 known vulnerabilities affecting gnu/libextractor.

Total CVEs
29
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH11MEDIUM14LOW1

Vulnerabilities

Page 2 of 2
CVE-2018-14347P4MEDIUMCVSS 6.5fixed in 1.72018-07-17
CVE-2018-14347 [MEDIUM] CWE-835 CVE-2018-14347: GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).
nvdosv
CVE-2019-15531P4MEDIUMCVSS 6.5≤ 1.92019-08-23
CVE-2019-15531 [MEDIUM] CWE-125 CVE-2019-15531: GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
nvdosv
CVE-2017-17440P4MEDIUMCVSS 6.5v1.62017-12-06
CVE-2017-17440 [MEDIUM] CWE-476 CVE-2017-17440: GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.
nvdosv
CVE-2009-3736P4MEDIUMCVSS 6.9≥ 0, < 0.5.23+dfsg-42009-11-29
CVE-2009-3736 [MEDIUM] CVE-2009-3736: ltdl ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
osv
CVE-2017-15266P4MEDIUMCVSS 5.5v1.42017-10-11
CVE-2017-15266 [MEDIUM] CWE-369 CVE-2017-15266: In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor. In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
nvdosv
CVE-2005-3624P4MEDIUMCVSS 5.0≥ 0, < 0.5.9-12005-12-31
CVE-2005-3624 [MEDIUM] CVE-2005-3624: The CCITTFaxStream::CCITTFaxStream function in Stream The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
osv
CVE-2005-3626P4MEDIUMCVSS 5.0≥ 0, < 0.5.9-12005-12-31
CVE-2005-3626 [MEDIUM] CVE-2005-3626: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
osv
CVE-2017-15922P4MEDIUMCVSS 5.5v1.42017-10-26
CVE-2017-15922 [MEDIUM] CWE-125 CVE-2017-15922: In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.
nvdosv
CVE-2005-2097P4LOWCVSS 2.1≥ 0, < 0.5.8-12005-08-16
CVE-2005-2097 [LOW] CVE-2005-2097: xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
osv
Gnu Libextractor vulnerabilities | cvebase