Liblouis is a widely embedded open-source braille translation library that, despite a narrow product footprint, reaches a significant constituency through integration into assistive technologies, accessibility tools, and document processing pipelines. Its vulnerability profile is characterized by a recurring pattern of memory-safety issues—improper bounds restrictions, out-of-bounds reads and writes, and stack-based buffer overflows—reflecting the parsing complexity and legacy C codebase inherent to braille translation logic. A meaningful share of the vendor's CVEs reach critical severity, underscoring the risk posed by memory corruption in a library that processes untrusted input from documents and user-supplied content. Defenders should prioritize liblouis patches in accessibility stacks and dependent applications, particularly where the library processes external or user-controlled documents; live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liblouis over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15101CRITICAL A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or pot | Jul 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-11440HIGH Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c. | May 25, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-11410CRITICAL An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers to cause a denial of service (application | May 24, 2018 | 9.8 | 29 | NO | NO |
CVE-2022-26981HIGH Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c). | Mar 13, 2022 | 7.8 | 28 | NO | NO |
CVE-2018-12085HIGH Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440. | Jun 9, 2018 | 8.8 | 28 | NO | NO |
CVE-2014-8184HIGH A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file th | Aug 2, 2019 | 7.8 | 26 | NO | NO |
CVE-2018-11685HIGH Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c. | Jun 4, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-11684HIGH Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c. | Jun 4, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-11683HIGH Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440. | Jun 4, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-11577HIGH Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c. | May 31, 2018 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liblouis.
Media articles that mention a CVE ID that affects a product developed by Liblouis — matched by CVE ID, not by vendor name.