cbcvebase.
CVE-2008-2426
published 2008-06-02

CVE-2008-2426: Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly…

PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.75%
92.2th percentile
Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loader_pnm.c; or (2) a crafted XPM image, related to the load function in src/modules/loader_xpm.c.

Affected

12 ranges
VendorProductVersion rangeFixed in
carsten_haitzlerimlib2
debianimlib2< imlib2 1.4.0-1.2 (bookworm)imlib2 1.4.0-1.2 (bookworm)
debianimlib2< imlib2 1.4.0-1.1 (bookworm)imlib2 1.4.0-1.1 (bookworm)
enlightenmentimlib2
enlightenmentimlib2>= 0 < 1.4.0-1.11.4.0-1.1
enlightenmentimlib2>= 0 < 1.4.0-1.21.4.0-1.2
enlightenmentimlib2>= 0 < 1.4.0-1.11.4.0-1.1
enlightenmentimlib2>= 0 < 1.4.0-1.21.4.0-1.2
enlightenmentimlib2>= 0 < 1.4.0-1.11.4.0-1.1
enlightenmentimlib2>= 0 < 1.4.0-1.21.4.0-1.2
enlightenmentimlib2>= 0 < 1.4.0-1.11.4.0-1.1
enlightenmentimlib2>= 0 < 1.4.0-1.21.4.0-1.2

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.