Libelfin is a focused C++ library for parsing and manipulating ELF (Executable and Linkable Format) binaries, embedded in debugging tools, binary analysis frameworks, and low-level system utilities where its parsing logic sits in the path of untrusted binary input. Vulnerabilities in this component recur through injection issues, classic buffer overflows, and integer-overflow conditions that arise from the complexity of ELF format parsing and the memory-safety demands of a native-code library. Defenders who integrate this library should prioritize updates when handling untrusted or adversarially crafted binaries; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libelfin Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24180MEDIUM Libelfin v0.3 was discovered to contain an integer overflow in the load function at elf/mmap_loader.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a | Mar 14, 2023 | 6.5 | 21 | NO | NO |
CVE-2020-24824MEDIUM A global buffer overflow issue in the dwarf::line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS). | Aug 4, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-24823MEDIUM A vulnerability in the dwarf::to_string function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file. | Aug 4, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-24822MEDIUM A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file. | Aug 4, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-24821MEDIUM A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file. | Aug 4, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-24827MEDIUM A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file. | Aug 4, 2021 | 5.5 | 19 | NO | NO |
CVE-2020-24826MEDIUM A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file. | Aug 4, 2021 | 5.5 | 19 | NO | NO |
CVE-2020-24825MEDIUM A vulnerability in the line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file. | Aug 4, 2021 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libelfin Project.
Media articles that mention a CVE ID that affects a product developed by Libelfin Project — matched by CVE ID, not by vendor name.