The Lief Project maintains a specialized binary-analysis and parsing library that, despite a narrow product scope, serves as a foundational tool across security research, reverse-engineering, and toolchain workflows. Its placement in security-critical infrastructure and development pipelines makes it a notable entity in the vulnerability landscape despite its modest disclosure volume. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lief Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38495HIGH LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c. | Sep 13, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-38306HIGH LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc. | Sep 13, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-32297HIGH An issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an attacker to cause code Execution. | Sep 20, 2021 | 8.8 | 25 | NO | NO |
CVE-2022-40922MEDIUM A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a cra | Oct 3, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-43171MEDIUM A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted Mach | Nov 17, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-40923MEDIUM A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a | Sep 30, 2022 | 6.5 | 22 | NO | NO |
CVE-2025-15504MEDIUM A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::parse_binary of the file src/ELF/Parser.tcc of the component E | Jan 10, 2026 | 5.5 | 21 | NO | NO |
CVE-2022-38307MEDIUM LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO/SegmentCommand.cpp. | Sep 13, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-38497MEDIUM LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69. | Sep 13, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-38496MEDIUM LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp. | Sep 13, 2022 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lief Project.
Media articles that mention a CVE ID that affects a product developed by Lief Project — matched by CVE ID, not by vendor name.