ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-2924
+1 in the same advisory: …2923
An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3.

An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.

NVD description · AI analysis pending
8.83%
  • freexl project freexl
  • freexl project debian linux
CVE-2018-7439
+4 in the same advisory: …7436 …7435 …7438 …7437
An issue was discovered in FreeXL before 1.0.5.

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record.

NVD description · AI analysis pending
8.82% PoC
  • freexl project freexl
  • freexl project debian linux