Libesedb Project maintains a specialized library for parsing the Extensible Storage Engine (ESE) database format, a narrow but strategically important component given ESE's presence in Microsoft Exchange and Windows systems. The disclosed vulnerability pattern centers on out-of-bounds read conditions, reflecting the parsing complexity inherent to a binary database format handler. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libesedb Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15161MEDIUM The libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NOTE | Sep 1, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-15160MEDIUM The libesedb_catalog_definition_read function in libesedb_catalog_definition.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a c | Sep 1, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-15159MEDIUM The libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NOTE | Sep 1, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-15158MEDIUM The libesedb_page_read_values function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NO | Sep 1, 2018 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libesedb Project.
Media articles that mention a CVE ID that affects a product developed by Libesedb Project — matched by CVE ID, not by vendor name.