Ledger CLI is a command-line accounting and finance tool that maintains a narrow but specialized user base among financial professionals and open-source accounting practitioners. While the product remains narrowly scoped, its role in personal and organizational financial record-keeping warrants attention to its security advisories; live vulnerability counts, severity, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ledger Cli over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2808HIGH An exploitable use-after-free vulnerability exists in the account parsing component of the Ledger-CLI 3.1.1. A specially crafted ledger file can cause a use-after-free vulnerabilit | Sep 5, 2017 | 7.8 | 25 | NO | NO |
CVE-2017-12482HIGH The ledger::parse_date_mask_routine function in times.cc in Ledger 3.1.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or | Aug 4, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-2807HIGH An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal file can cause an integer underflow resulting | Sep 5, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-12481HIGH The find_option function in option.cc in Ledger 3.1.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unsp | Aug 4, 2017 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ledger Cli.
Media articles that mention a CVE ID that affects a product developed by Ledger Cli — matched by CVE ID, not by vendor name.