Boost is a collection of peer-reviewed C++ libraries widely embedded in systems software and applications, where its narrow product scope masks pervasive downstream deployment across the technology landscape. Observed vulnerabilities concentrate on input-validation issues affecting core components such as the regex and memory-pool libraries, reflecting the parsing and resource-management demands of low-level C++ abstractions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boost over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9840HIGH inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | May 23, 2017 | 8.8 | 33 | NO | NO |
CVE-2008-0171MEDIUM regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed | Jan 17, 2008 | 5.0 | 19 | NO | NO |
CVE-2012-2677MEDIUM Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks su | Jul 25, 2012 | 5.0 | 18 | NO | NO |
CVE-2013-0252MEDIUM boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which might allow remote attackers t | Mar 12, 2013 | 5.0 | 17 | NO | NO |
CVE-2008-0172MEDIUM The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of | Jan 17, 2008 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boost.
Media articles that mention a CVE ID that affects a product developed by Boost — matched by CVE ID, not by vendor name.