Liblnk is a specialized library for parsing Windows shortcut (.lnk) files, a narrow but strategically important component embedded across forensic tools, file managers, and security utilities that process untrusted link metadata. Its observed vulnerabilities center on memory-handling and information-disclosure weaknesses—out-of-bounds reads, exposure of sensitive information, and incorrect calculations—characteristic of binary parsing logic operating on potentially malformed input. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liblnk Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12098MEDIUM The liblnk_data_block_read function in liblnk_data_block.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via | Jun 19, 2018 | 5.5 | 19 | NO | NO |
CVE-2018-12096MEDIUM The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buf | Jun 19, 2018 | 5.5 | 19 | NO | NO |
CVE-2018-12097MEDIUM The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-ba | Jun 19, 2018 | 5.5 | 18 | NO | NO |
In libyal liblnk before 20191006, liblnk_location_information_read_data in liblnk_location_information.c has a heap-based buffer over-read because an incorrect variable name is use | Oct 6, 2019 | 3.3 | 16 | NO | NO |
libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_location_information_read_data in liblnk_location_information.c, a | Oct 9, 2019 | 3.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liblnk Project.
Media articles that mention a CVE ID that affects a product developed by Liblnk Project — matched by CVE ID, not by vendor name.