file_project CVE Vulnerabilities & Metrics

Focus on file_project vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About file_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with file_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total file_project CVEs: 12
Earliest CVE date: 14 Mar 2014, 15:55 UTC
Latest CVE date: 22 Aug 2023, 19:16 UTC

Latest CVE reference: CVE-2022-48554

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical file_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.65

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 13
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS file_project CVEs

These are the five CVEs with the highest CVSS scores for file_project, sorted by severity first and recency.

All CVEs for file_project

CVE-2022-48554 file_project vulnerability CVSS: 0 22 Aug 2023, 19:16 UTC

File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.

CVE-2019-18218 file_project vulnerability CVSS: 6.8 21 Oct 2019, 05:15 UTC

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

CVE-2019-8907 file_project vulnerability CVSS: 6.8 18 Feb 2019, 17:29 UTC

do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.

CVE-2019-8906 file_project vulnerability CVSS: 3.6 18 Feb 2019, 17:29 UTC

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

CVE-2019-8905 file_project vulnerability CVSS: 3.6 18 Feb 2019, 17:29 UTC

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

CVE-2019-8904 file_project vulnerability CVSS: 6.8 18 Feb 2019, 17:29 UTC

do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.

CVE-2018-10360 file_project vulnerability CVSS: 4.3 11 Jun 2018, 10:29 UTC

The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVE-2017-1000249 file_project vulnerability CVSS: 2.1 11 Sep 2017, 19:29 UTC

An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. This was fixed in commit 35c94dc6acc418f1ad7f6241a6680e5327495793 (Aug 2017).

CVE-2014-9653 file_project vulnerability CVSS: 7.5 30 Mar 2015, 10:59 UTC

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

CVE-2014-9652 file_project vulnerability CVSS: 5.0 30 Mar 2015, 10:59 UTC

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

CVE-2014-9621 file_project vulnerability CVSS: 5.0 21 Jan 2015, 18:59 UTC

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

CVE-2014-9620 file_project vulnerability CVSS: 5.0 21 Jan 2015, 18:59 UTC

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

CVE-2014-8117 file_project vulnerability CVSS: 5.0 17 Dec 2014, 19:59 UTC

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

CVE-2014-8116 file_project vulnerability CVSS: 5.0 17 Dec 2014, 19:59 UTC

The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.

CVE-2014-3487 file_project vulnerability CVSS: 4.3 09 Jul 2014, 11:07 UTC

The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.

CVE-2014-3480 file_project vulnerability CVSS: 4.3 09 Jul 2014, 11:07 UTC

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.

CVE-2014-3479 file_project vulnerability CVSS: 4.3 09 Jul 2014, 11:07 UTC

The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.

CVE-2014-2270 file_project vulnerability CVSS: 4.3 14 Mar 2014, 15:55 UTC

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.