Libsolv

Vendor:

First CVE: Dec 28, 2018 · Active for 7 years

13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libsolv over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2018
7 years ago
Most Recent CVE
May 26, 2026
59 days ago

CVE Severity & Scoring

Libsolv13 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local2 (15.4%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (38.5%)
Unknown0 (0.0%)
Required8 (61.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None13 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validat
May 26, 20267.833NONO
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_ad
May 21, 20266.531NONO
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata.
May 20, 20266.530NONO
repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.
Jan 21, 20207.525NONO
Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Sep 2, 20217.524NONO
Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Sep 2, 20217.524NONO
Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Sep 2, 20217.524NONO
Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Sep 2, 20217.524NONO
Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940
Feb 21, 20226.522NONO
There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that
Dec 28, 20186.522NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Libsolv

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.7.3617.80.2%00