The File utility is a foundational command-line tool present across Unix and Unix-like systems, used to identify file types by examining content rather than extensions. Vulnerabilities affecting this tool reflect its role as a parsing engine for diverse binary and text formats, and its exposure has centered on the file-identification product itself; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by File over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1304HIGH Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file. | Jan 10, 2005 | 10.0 | 47 | NO | YES |
CVE-2007-1536HIGH Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffe | Mar 20, 2007 | 9.3 | 41 | NO | YES |
CVE-2019-18218HIGH cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). | Oct 21, 2019 | 7.8 | 26 | NO | NO |
CVE-2019-8907HIGH do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified othe | Feb 18, 2019 | 8.8 | 24 | NO | NO |
CVE-2019-8904HIGH do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf. | Feb 18, 2019 | 8.8 | 22 | NO | NO |
CVE-2018-10360MEDIUM The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF | Jun 11, 2018 | 6.5 | 22 | NO | NO |
CVE-2003-0102MEDIUM Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF h | Mar 18, 2003 | 4.6 | 22 | NO | YES |
CVE-2014-9653HIGH readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes rea | Mar 30, 2015 | 7.5 | 21 | NO | NO |
CVE-2014-3480MEDIUM The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count d | Jul 9, 2014 | 6.5 | 21 | NO | NO |
CVE-2017-1000249MEDIUM An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .n | Sep 11, 2017 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by File.
Media articles that mention a CVE ID that affects a product developed by File — matched by CVE ID, not by vendor name.