Librdf is a niche RDF parsing and manipulation library whose vulnerability footprint concentrates in the Raptor RDF syntax parser, a component embedded in semantic-web and linked-data applications. The recurring weakness classes—out-of-bounds read and write conditions, improper input validation, XML entity reference handling, and integer wraparound—reflect the parsing and state-management complexity inherent to RDF format processing. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Librdf over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0037MEDIUM Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remot | Jun 17, 2012 | 6.5 | 29 | NO | NO |
CVE-2017-18926HIGH raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap- | Nov 6, 2020 | 7.1 | 25 | NO | NO |
CVE-2020-25713MEDIUM A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common. | May 13, 2021 | 6.5 | 23 | NO | NO |
CVE-2024-57823MEDIUM In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path(). | Jan 10, 2025 | 5.5 | 19 | NO | NO |
CVE-2024-57822MEDIUM In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal(). | Jan 10, 2025 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Librdf.
Media articles that mention a CVE ID that affects a product developed by Librdf — matched by CVE ID, not by vendor name.