CVE-2020-18900: Libexe Project Libexe

Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128. NOTE: the vendor has disputed this as described in libyal/libexe issue 1 on GitHub

Affected products

Published 2021-08-19. Last modified 2026-06-17.