Leanify Project maintains a file-optimization utility designed to reduce the size of various media and document formats, a narrowly scoped tool that nonetheless carries memory-safety implications given its role in parsing and rewriting binary structures. The observed vulnerability surface centers on out-of-bounds write conditions, a class of flaw that reflects the low-level buffer manipulation inherent to format-processing code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leanify Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12835CRITICAL formats/xml.cpp in Leanify 0.4.3 allows for a controlled out-of-bounds write in xml_memory_writer::write via characters that require escaping. | Jun 15, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-12298MEDIUM Leanify 0.4.3 allows remote attackers to trigger an out-of-bounds write (1024 bytes) via a modified input file. | May 23, 2019 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leanify Project.
Media articles that mention a CVE ID that affects a product developed by Leanify Project — matched by CVE ID, not by vendor name.