Catdoc
Vendor:
First CVE: Jul 8, 2017 · Active for 9 years
6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Catdoc over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 8, 2017
9 years ago
Most Recent CVE
Jun 2, 2025
417 days ago
CVE Severity & Scoring
Catdoc6 CVEs
17%
83%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (83.3%)
Network1 (16.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None4 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31979HIGH Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c. | May 9, 2023 | 7.8 | 24 | NO | NO |
CVE-2024-54028HIGH An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption | Jun 2, 2025 | 7.8 | 23 | NO | NO |
CVE-2024-52035HIGH An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based me | Jun 2, 2025 | 7.8 | 23 | NO | NO |
CVE-2023-46345HIGH Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c. | Oct 26, 2023 | 7.5 | 21 | NO | NO |
CVE-2017-11110HIGH The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified | Jul 8, 2017 | 7.8 | 20 | NO | NO |
CVE-2023-41633MEDIUM Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c. | Sep 1, 2023 | 5.5 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Catdoc
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.95 | 6 | 7.4 | 0.5% | 0 | 0 |