Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

File Project

First CVE: Mar 18, 2003Active for: 23 yearsTotal CVEs: 23
29.4
VTI Score
Low

The File Project maintains a widely deployed file-type analysis and identification utility that serves as a foundational component across Unix-like systems, development toolchains, and forensic platforms. Its vulnerability footprint centers on the core file product and recurs through memory-safety and input-handling weakness classes including out-of-bounds reads and writes, improper input validation, and memory buffer boundary violations, reflecting the parser complexity inherent to file-format detection across thousands of format signatures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 95% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by File Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2003
23 years ago
Most Recent CVE
Aug 22, 2023
1,067 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1304HIGH
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
Jan 10, 200510.047NOYES
CVE-2007-1536HIGH
Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffe
Mar 20, 20079.341NOYES
CVE-2019-18218HIGH
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Oct 21, 20197.826NONO
CVE-2019-8907HIGH
do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified othe
Feb 18, 20198.824NONO
CVE-2019-8904HIGH
do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.
Feb 18, 20198.822NONO
CVE-2018-10360MEDIUM
The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF
Jun 11, 20186.522NONO
CVE-2003-0102MEDIUM
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF h
Mar 18, 20034.622NOYES
CVE-2014-9653HIGH
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes rea
Mar 30, 20157.521NONO
CVE-2014-3480MEDIUM
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count d
Jul 9, 20146.521NONO
CVE-2017-1000249MEDIUM
An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .n
Sep 11, 20175.520NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
74%
26%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (21.7%)
Network5 (21.7%)
Unknown13 (56.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (39.1%)
High1 (4.3%)
Unknown13 (56.5%)
User Interaction
None4 (17.4%)
Unknown13 (56.5%)
Required6 (26.1%)
Privileges Required
Low3 (13.0%)
High0 (0.0%)
None7 (30.4%)
Unknown13 (56.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by File Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by File Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For File Project's Products

View all 4 CNAs →

Top CWEs