CVE-2020-18900: Libexe Project Libexe
Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128. NOTE: the vendor has disputed this as described in libyal/libexe issue 1 on GitHub
Affected products
- Libexe Project Libexe: before 20181128 (fixed in 20181128)
Published 2021-08-19. Last modified 2026-06-17.