Freexl is a niche library for parsing Microsoft Excel spreadsheets, and despite its narrow product scope sits in the software supply chain of geospatial and data-processing applications that depend on it. Its vulnerability profile centers on memory-safety issues, particularly out-of-bounds reads and writes arising from malformed file parsing, which reflect the complexity of handling legacy binary spreadsheet formats. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freexl Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7439HIGH An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record. | Feb 23, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-7438HIGH An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string function. | Feb 23, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-7437HIGH An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function. | Feb 23, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-7436HIGH An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function. | Feb 23, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-7435HIGH An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function. | Feb 23, 2018 | 8.8 | 26 | NO | NO |
CVE-2017-2924HIGH An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resultin | Apr 24, 2018 | 8.8 | 24 | NO | NO |
CVE-2017-2923HIGH An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption r | Apr 24, 2018 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freexl Project.
Media articles that mention a CVE ID that affects a product developed by Freexl Project — matched by CVE ID, not by vendor name.