Libpff Project maintains a specialized library for parsing Microsoft Outlook personal folder (.pff) files, a narrow but structurally important component in forensic and email-recovery workflows. The recurring vulnerability signal centers on memory-safety issues including infinite loops, out-of-bounds reads, and use-after-free conditions, reflecting the parsing complexity inherent to handling untrusted binary file formats; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libpff Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-18897HIGH An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitra | Aug 19, 2021 | 7.8 | 25 | NO | NO |
CVE-2018-20348MEDIUM libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite recursion) via a crafted file, rel | Dec 22, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-11723MEDIUM The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based | Jun 19, 2018 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libpff Project.
Media articles that mention a CVE ID that affects a product developed by Libpff Project — matched by CVE ID, not by vendor name.