Lizard Project maintains a compression library focused on the LZ5 format and related tools, a narrowly scoped but strategically embedded component that can propagate exposure across dependent applications. The durable signal centers on memory-safety issues inherent to compression parsing, with recurring weakness classes including improper bounds checking and out-of-bounds reads that reflect the low-level buffer manipulation demands of codec implementation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lizard Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16985HIGH In Lizard (formerly LZ5) 2.0, use of an invalid memory address was discovered in LZ5_compress_continue in lz5_compress.c, related to LZ5_compress_fastSmall and MEM_read32. The vuln | Sep 13, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-11498HIGH In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size during a memcpy in the Lizard_decompress_LIZv1 function (lib/liza | May 26, 2018 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lizard Project.
Media articles that mention a CVE ID that affects a product developed by Lizard Project — matched by CVE ID, not by vendor name.