CVE-2023-49287: Cxong Tinydir

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.

Affected products

  • Cxong Tinydir: before 1.2.6 (fixed in 1.2.6)

Published 2023-12-04. Last modified 2026-06-17.