Vulnerabilities (CVE)

Filtered by vendor Ledger-cli Subscribe
Filtered by product Ledger
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-2807 1 Ledger-cli 1 Ledger 2024-02-04 6.8 MEDIUM 7.8 HIGH
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal file can cause an integer underflow resulting in code execution. An attacker can construct a malicious journal file to trigger this vulnerability.
CVE-2017-2808 1 Ledger-cli 1 Ledger 2024-02-04 6.8 MEDIUM 7.8 HIGH
An exploitable use-after-free vulnerability exists in the account parsing component of the Ledger-CLI 3.1.1. A specially crafted ledger file can cause a use-after-free vulnerability resulting in arbitrary code execution. An attacker can convince a user to load a journal file to trigger this vulnerability.
CVE-2017-12482 1 Ledger-cli 1 Ledger 2024-02-04 6.8 MEDIUM 7.8 HIGH
The ledger::parse_date_mask_routine function in times.cc in Ledger 3.1.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
CVE-2017-12481 1 Ledger-cli 1 Ledger 2024-02-04 6.8 MEDIUM 7.8 HIGH
The find_option function in option.cc in Ledger 3.1.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.