Libwmf

Vendor:

First CVE: Jul 6, 2006 · Active for 20 years

6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libwmf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 6, 2006
20 years ago
Most Recent CVE
Mar 23, 2017
3,412 days ago

CVE Severity & Scoring

Libwmf6 CVEs
All CVEs352,719 CVEs
MediumHigh
Attack Vector
Local1 (16.7%)
Network0 (0.0%)
Unknown5 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (16.7%)
High0 (0.0%)
Unknown5 (83.3%)
User Interaction
None0 (0.0%)
Unknown5 (83.3%)
Required1 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (16.7%)
Unknown5 (83.3%)

Top CVEs

Signals from CVEs in this product scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
Jul 1, 20156.827NONO
Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote at
Jul 6, 20067.523NONO
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a craft
Jul 1, 20156.821NONO
The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (application crash) via a crafted wmf file, which triggers a memory allocati
Mar 23, 20175.520NONO
meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
Jul 1, 20155.017NONO
Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.
Jul 1, 20154.315NONO

Exploit Exposure

Signals from CVEs in this product scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (6 CVEs).

Media Mentions

Signals from CVEs in this product scope (6 CVEs).

Top CNAs Publishing CVEs For Libwmf

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.2.8.455.76.6%00
0.2.8_.417.57.8%00