Liblas is a specialized geospatial library for parsing and manipulating LiDAR point-cloud data, with a narrow but strategically important role in GIS, surveying, and remote-sensing applications. Its durable signal centers on memory-safety and input-handling weaknesses, including improper input validation, memory-management defects such as missing resource release and use-after-free conditions, and out-of-bounds reads that are characteristic of C/C++ parsers handling complex binary formats. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liblas over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20540MEDIUM There is memory leak at liblas::Open (liblas/liblas.hpp) in libLAS 1.8.1. | Dec 28, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-20539MEDIUM There is a Segmentation fault triggered by illegal address access at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service. | Dec 28, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-20537MEDIUM There is a NULL pointer dereference at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service. | Dec 28, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-20536MEDIUM There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service. | Dec 28, 2018 | 6.5 | 22 | NO | NO |
CVE-2024-27507HIGH libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp. | Feb 27, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liblas.
Media articles that mention a CVE ID that affects a product developed by Liblas — matched by CVE ID, not by vendor name.