Libical is a widely embedded calendar and scheduling library that, despite a narrow product scope, sits deep in mail clients, calendar applications, and groupware systems across many platforms. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-safety weakness classes such as out-of-bounds reads and use-after-free conditions that reflect the parsing complexity of iCalendar format handling. Defenders should inventory applications that depend on this library and prioritize updates, since a single flaw can propagate across every downstream product that links it; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libical Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9584CRITICAL libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file. | Jan 18, 2017 | 9.1 | 23 | NO | NO |
CVE-2016-5826HIGH The parser_get_next_char function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) by crafting a string to the icalparser_pars | Jan 27, 2017 | 7.5 | 21 | NO | NO |
CVE-2016-5827HIGH The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_pars | Jan 27, 2017 | 7.5 | 20 | NO | NO |
CVE-2016-5824MEDIUM libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file. | Jan 27, 2017 | 5.5 | 19 | NO | NO |
CVE-2016-5823MEDIUM The icalproperty_new_clone function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file. | Jan 27, 2017 | 5.5 | 19 | NO | NO |
CVE-2016-5825MEDIUM The icalparser_parse_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted ics file. | Jan 27, 2017 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libical Project.
Media articles that mention a CVE ID that affects a product developed by Libical Project — matched by CVE ID, not by vendor name.