Search CVE reports


Toggle filters

1 – 10 of 11 results


CVE-2024-54028

Medium priority

Some fixes available 5 of 8

An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to...

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-52035

Medium priority

Some fixes available 5 of 8

An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a...

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-48877

Medium priority

Some fixes available 5 of 8

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a...

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-46345

Medium priority
Needs evaluation

Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-41633

Medium priority
Needs evaluation

Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c.

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-31979

Medium priority
Needs evaluation

Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c.

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-7233

Low priority
Needs evaluation

In libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference.

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-7156

Low priority
Vulnerable

In libdoc through 2019-01-28, calcFileBlockOffset in ole.c allows division by zero.

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2018-20453

Low priority
Needs evaluation

The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-20451

Low priority
Needs evaluation

The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

1 affected package

catdoc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catdoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages