Libemf Project maintains a library for reading and writing Enhanced Metafile (EMF) format documents, a narrowly scoped component with high visibility in graphics and document-processing pipelines. Observed vulnerabilities cluster around memory-safety issues—including buffer boundary violations, integer overflows, and use-after-free conditions—reflecting the parsing and format-handling complexity inherent to binary file processing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libemf Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11866HIGH libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free. | May 11, 2020 | 7.8 | 26 | NO | NO |
CVE-2020-11865HIGH libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access. | May 11, 2020 | 7.8 | 26 | NO | NO |
CVE-2020-11864MEDIUM libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2). | May 11, 2020 | 5.5 | 21 | NO | NO |
CVE-2020-11863MEDIUM libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2). | May 11, 2020 | 5.5 | 21 | NO | NO |
CVE-2020-13999MEDIUM ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file. | Jun 15, 2020 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libemf Project.
Media articles that mention a CVE ID that affects a product developed by Libemf Project — matched by CVE ID, not by vendor name.