Libdoc is a niche document-processing library with a focused vulnerability footprint concentrated in its core product, where observed weaknesses center on memory-safety and state-handling issues such as out-of-bounds reads, divide-by-zero conditions, and NULL pointer dereferences. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libdoc Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7233HIGH In libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference. | Jan 30, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-20453MEDIUM The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a craft | Dec 25, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-20451MEDIUM The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a cr | Dec 25, 2018 | 6.5 | 22 | NO | NO |
CVE-2019-7156MEDIUM In libdoc through 2019-01-28, calcFileBlockOffset in ole.c allows division by zero. | Jan 29, 2019 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libdoc Project.
Media articles that mention a CVE ID that affects a product developed by Libdoc Project — matched by CVE ID, not by vendor name.