Zbar Project maintains a narrowly scoped barcode-scanning library that, despite limited disclosure volume, serves as a dependency across barcode-reading applications and embedded systems. The vulnerability signal centers on the library's parser implementation, with observed exposure in out-of-bounds write conditions that can arise from malformed barcode input. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zbar Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40890CRITICAL A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary c | Aug 29, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-40889CRITICAL A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code exe | Aug 29, 2023 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zbar Project.
Media articles that mention a CVE ID that affects a product developed by Zbar Project — matched by CVE ID, not by vendor name.