CVE-2023-46345 (https://gist.github.com/rycbar77/d747b2c37b544ece30b2353a65ab41f9): Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c. No evidence of an upstream report or fix, while apparently the upstream bug tracker and wiki are broken, and no update since 2016. Time for last rites?
CVE-2023-41633 (https://rycbar77.github.io/2023/08/29/catdoc-0-95-nullptr-dereference/): Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c.