Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lief Project

First CVE: Sep 20, 2021Active for: 5 yearsTotal CVEs: 22

The Lief Project maintains a specialized binary-analysis and parsing library that, despite a narrow product scope, serves as a foundational tool across security research, reverse-engineering, and toolchain workflows. Its placement in security-critical infrastructure and development pipelines makes it a notable entity in the vulnerability landscape despite its modest disclosure volume. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lief Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 20, 2021
4 years ago
Most Recent CVE
Jan 10, 2026
195 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-38495HIGH
LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.
Sep 13, 20227.825NONO
CVE-2022-38306HIGH
LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.
Sep 13, 20227.825NONO
CVE-2021-32297HIGH
An issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an attacker to cause code Execution.
Sep 20, 20218.825NONO
CVE-2022-40922MEDIUM
A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a cra
Oct 3, 20226.523NONO
CVE-2022-43171MEDIUM
A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted Mach
Nov 17, 20226.522NONO
CVE-2022-40923MEDIUM
A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a
Sep 30, 20226.522NONO
CVE-2025-15504MEDIUM
A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::parse_binary of the file src/ELF/Parser.tcc of the component E
Jan 10, 20265.521NONO
CVE-2022-38307MEDIUM
LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO/SegmentCommand.cpp.
Sep 13, 20225.521NONO
CVE-2022-38497MEDIUM
LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.
Sep 13, 20225.520NONO
CVE-2022-38496MEDIUM
LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.
Sep 13, 20225.516NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
9%
64%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local7 (63.6%)
Network4 (36.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (9.1%)
Unknown0 (0.0%)
Required10 (90.9%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None9 (81.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lief Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lief Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lief Project's Products

View all 2 CNAs →

Top CWEs