Libofx Project maintains a specialized financial-data parsing library used for OFX (Open Financial Exchange) format conversion and import across banking and financial applications. Its vulnerability profile centers on memory-safety issues endemic to the library's C implementation, with recurring weakness classes including buffer-boundary violations, NULL-pointer dereferences, and out-of-bounds reads that arise during untrusted file parsing. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libofx Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9656HIGH An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump. | Mar 11, 2019 | 8.8 | 25 | NO | NO |
CVE-2017-2816HIGH An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a b | Sep 13, 2017 | 8.8 | 24 | NO | NO |
CVE-2017-14731MEDIUM ofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as de | Sep 25, 2017 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libofx Project.
Media articles that mention a CVE ID that affects a product developed by Libofx Project — matched by CVE ID, not by vendor name.