Vulnerabilities in libvips
12 resultsVexday analysis
libvips registra 7 vulnerabilidades no histórico com 4 publicações nos últimos 90 dias, indicando atividade recente de descobertas. Nenhuma vulnerabilidade está sob ataque ativo (KEV) e não há críticas classificadas, reduzindo a urgência imediata. A fraqueza dominante é CWE-122 (buffer overflow), exigindo atenção à integridade de entrada de dados nas operações de processamento de imagem.
CVE-2025-29769HIGHlibvips has a potential heap-based buffer overflow when attempting to convert multiband TIFF input to HEIF outputEPSS 0.3%CVE-2023-40032MEDIUMPotential segfault due to NULL pointer dereference in libvipsEPSS 0.3%CVE-2026-69242HIGHlibvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident writeEPSS 0.2%CVE-2025-59933MEDIUMlibvips is vulnerable to Buffer Over-Read in poppler-based pdfloadEPSS 0.2%CVE-2026-35591HIGHPossible heap-based buffer overflow when decoding TIFF image containing well-crafted tileEPSS 0.2%CVE-2026-33327HIGHPossible integer overflow leading to potential heap-based buffer overflowEPSS 0.2%CVE-2026-35590MEDIUMPossible out-of-bounds read leading to crash when decoding well-crafted EXIF metadataEPSS 0.1%CVE-2026-33328MEDIUMPossible integer overflow on 32-bit systems when reading GIF imagesEPSS 0.1%CVE-2026-70653MEDIUMlibvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radiance imageEPSS 0.1%CVE-2026-70651MEDIUMlibvips: Possible integer overflow when reading multi-page TIFF images via ImageMagickEPSS 0.1%CVE-2026-70652LOWlibvips: Possible heap-based buffer read overflow when resizing and re-encoding a JPEG with gain mapEPSS 0.1%CVE-2026-70654MEDIUMlibvips: A well-crafted PPM image processed via a custom source could lead to possible heap buffer write overflowEPSS 0.1%