Md2roff Project maintains a markdown-to-roff conversion utility with a narrow but specialized footprint in documentation toolchains. The observed vulnerability signal centers on an out-of-bounds write weakness, reflecting the memory-handling demands inherent to format-conversion parsing. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Md2roff Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34913CRITICAL md2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to be processed. NOTE: the vendor's position is that the produ | Jul 2, 2022 | 9.8 | 25 | NO | NO |
CVE-2022-41220CRITICAL md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended fo | Sep 21, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Md2roff Project.
Media articles that mention a CVE ID that affects a product developed by Md2roff Project — matched by CVE ID, not by vendor name.