VendorsLIEF-Projectliefall versions
Vulnerabilities

LIEF-Project LIEF (Library to Instrument Executable Formats)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-32297
An issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an attacker to cause code Execution.
Published 2021-09-20 · Modified
8.8EPSS 0.016
CVE-2022-38306
LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.
Published 2022-09-13 · Modified
7.8EPSS 0.003
CVE-2022-38495
LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.
Published 2022-09-13 · Modified
7.8EPSS 0.003
CVE-2022-43171
A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted MachO file.
Published 2022-11-17 · Modified
6.5EPSS 0.007
CVE-2022-40923
A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file.
Published 2022-09-30 · Modified
6.5EPSS 0.006
CVE-2022-40922
A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file.
Published 2022-10-03 · Modified
6.5EPSS 0.006
CVE-2022-38307
LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO/SegmentCommand.cpp.
Published 2022-09-13 · Modified
5.5EPSS 0.003
CVE-2022-38497
LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.
Published 2022-09-13 · Modified
5.5EPSS 0.003
CVE-2022-38496
LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.
Published 2022-09-13 · Modified
5.5EPSS 0.003
CVE-2025-15504
lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference
Published 2026-01-10 · Modified
5.5EPSS 0.003
CVE-2024-31636
An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.
Published 2024-05-03 · Modified
3.9EPSS 0.002