File
Vendor:
First CVE: Mar 18, 2003 · Active for 23 years
22
Total CVEs
More Total CVEs than 93% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact File over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2003
23 years ago
Most Recent CVE
Aug 22, 2023
1,068 days ago
CVE Severity & Scoring
File22 CVEs
73%
27%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (22.7%)
Network4 (18.2%)
Unknown13 (59.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (40.9%)
High0 (0.0%)
Unknown13 (59.1%)
User Interaction
None3 (13.6%)
Unknown13 (59.1%)
Required6 (27.3%)
Privileges Required
Low3 (13.6%)
High0 (0.0%)
None6 (27.3%)
Unknown13 (59.1%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1304HIGH Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file. | Jan 10, 2005 | 10.0 | 47 | NO | YES |
CVE-2007-1536HIGH Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffe | Mar 20, 2007 | 9.3 | 41 | NO | YES |
CVE-2019-18218HIGH cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). | Oct 21, 2019 | 7.8 | 26 | NO | NO |
CVE-2019-8907HIGH do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified othe | Feb 18, 2019 | 8.8 | 24 | NO | NO |
CVE-2019-8904HIGH do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf. | Feb 18, 2019 | 8.8 | 22 | NO | NO |
CVE-2018-10360MEDIUM The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF | Jun 11, 2018 | 6.5 | 22 | NO | NO |
CVE-2003-0102MEDIUM Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF h | Mar 18, 2003 | 4.6 | 22 | NO | YES |
CVE-2014-9653HIGH readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes rea | Mar 30, 2015 | 7.5 | 21 | NO | NO |
CVE-2014-3480MEDIUM The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count d | Jul 9, 2014 | 6.5 | 21 | NO | NO |
CVE-2017-1000249MEDIUM An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .n | Sep 11, 2017 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.6% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For File
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.41 | 1 | 5.5 | 0.7% | 0 | 0 |
| 5.35 | 4 | 6.6 | 1.7% | 0 | 0 |
| 5.33 | 1 | 6.5 | 3.4% | 0 | 0 |
| 5.29 | 1 | 5.5 | 0.4% | 0 | 0 |
| 5.21 | 2 | 5.0 | 3.8% | 0 | 0 |
| 5.20 | 3 | 5.0 | 4.0% | 0 | 0 |
| 5.19 | 2 | 5.0 | 3.8% | 0 | 0 |
| 5.18 | 2 | 5.0 | 3.8% | 0 | 0 |
| 5.17 | 2 | 5.0 | 3.8% | 0 | 0 |
| 5.16 | 2 | 5.0 | 3.8% | 0 | 0 |
| 5.15 | 1 | 5.0 | 4.7% | 0 | 0 |
| 5.14 | 1 | 5.0 | 4.7% | 0 | 0 |
| 5.13 | 1 | 5.0 | 4.7% | 0 | 0 |
| 5.12 | 1 | 5.0 | 4.7% | 0 | 0 |
| 5.11 | 1 | 5.0 | 4.7% | 0 | 0 |
| 5.10 | 1 | 5.0 | 4.7% | 0 | 0 |
| 5.09 | 1 | 5.0 | 4.7% | 0 | 0 |
| 5.08 | 1 | 5.0 | 4.7% | 0 | 0 |
| 4.9 | 1 | 10.0 | 11.4% | 0 | 1 |
| 4.8 | 1 | 10.0 | 11.4% | 0 | 1 |