Dcraw Project Dcraw vulnerabilities
9 known vulnerabilities affecting dcraw_project/dcraw.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2015-8366P3CRITICALCVSS 9.8≥ 0, < 9.28-12020-01-14
CVE-2015-8366 [CRITICAL] CVE-2015-8366: Array index error in smal_decode_segment function in LibRaw before 0
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.
osv
CVE-2018-19655P3HIGHCVSS 8.8≤ 9.282018-11-29
CVE-2018-19655 [HIGH] CWE-787 CVE-2018-19655: A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-b
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
nvdosv
CVE-2021-3624P3HIGHCVSS 7.8v9.28-2vdcraw 9.28-22022-04-18
CVE-2021-3624 [HIGH] CWE-20 CVE-2021-3624: There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously c
There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
nvdosv
CVE-2018-19565P4HIGHCVSS 7.1≤ 9.282018-11-26
CVE-2018-19565 [HIGH] CWE-125 CVE-2018-19565: A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to su
A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
nvd
CVE-2018-19566P4HIGHCVSS 7.1≤ 9.282018-11-26
CVE-2018-19566 [HIGH] CWE-125 CVE-2018-19566: A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to s
A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
nvd
CVE-2015-3885P4MEDIUMCVSS 4.3≤ 7.002015-05-19
CVE-2015-3885 [MEDIUM] CWE-189 CVE-2015-3885: Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to ca
Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
nvdosv
CVE-2018-19568P4MEDIUMCVSS 5.5≤ 9.282018-11-26
CVE-2018-19568 [MEDIUM] CWE-119 CVE-2018-19568: A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers a
A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
nvd
CVE-2018-19567P4MEDIUMCVSS 5.5≤ 9.282018-11-26
CVE-2018-19567 [MEDIUM] CWE-119 CVE-2018-19567: A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able t
A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
nvd
CVE-2013-1438P4MEDIUMCVSS 4.3≥ 0, < 9.28-12014-01-19
CVE-2013-1438 [MEDIUM] CVE-2013-1438: Unspecified vulnerability in dcraw 0
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
osv