Libextractor
Vendor:
First CVE: Oct 11, 2017 · Active for 8 years
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libextractor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 11, 2017
8 years ago
Most Recent CVE
Aug 23, 2019
2,527 days ago
CVE Severity & Scoring
Libextractor13 CVEs
54%
46%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (15.4%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (30.8%)
Unknown0 (0.0%)
Required9 (69.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None13 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16430HIGH GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c. | Sep 4, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-14346HIGH GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c). | Jul 17, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-15267HIGH In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c. | Oct 11, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-17440MEDIUM GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Screa | Dec 6, 2017 | 6.5 | 24 | NO | NO |
CVE-2017-15602HIGH In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite l | Oct 18, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-15601HIGH In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to processiTXt and stndup. | Oct 18, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-15600HIGH In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c. | Oct 18, 2017 | 7.5 | 24 | NO | NO |
CVE-2019-15531MEDIUM GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c. | Aug 23, 2019 | 6.5 | 23 | NO | NO |
CVE-2018-20431MEDIUM GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c. | Dec 24, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-20430MEDIUM GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in c | Dec 24, 2018 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Libextractor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6 | 1 | 6.5 | 2.4% | 0 | 0 |
| 1.4 | 6 | 6.8 | 1.8% | 0 | 0 |