Vulnerabilities
Vulnerable Software
Fossies:  >> Catdoc  >> 0.95  Security Vulnerabilities
An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
CVSS Score
8.4
EPSS Score
0.001
Published
2025-06-02
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
CVSS Score
8.4
EPSS Score
0.001
Published
2025-06-02
Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-10-26
Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-09-01
Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c.
CVSS Score
7.8
EPSS Score
0.001
Published
2023-05-09
The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted file, i.e., data is written to memory addresses before the beginning of the tmpBuf buffer.
CVSS Score
7.8
EPSS Score
0.002
Published
2017-07-08


Contact Us

Shodan ® - All rights reserved