Dcraw Project Dcraw vulnerabilities

7 known vulnerabilities affecting dcraw_project/dcraw.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2021-3624HIGHCVSS 7.8v9.28-22022-04-18
CVE-2021-3624 [HIGH] CWE-20 CVE-2021-3624: There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously c There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
nvd
CVE-2018-19655HIGHCVSS 8.8≤ 9.282018-11-29
CVE-2018-19655 [HIGH] CWE-787 CVE-2018-19655: A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-b A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
nvd
CVE-2018-19565HIGHCVSS 7.1≤ 9.282018-11-26
CVE-2018-19565 [HIGH] CWE-125 CVE-2018-19565: A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to su A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
nvd
CVE-2018-19566HIGHCVSS 7.1≤ 9.282018-11-26
CVE-2018-19566 [HIGH] CWE-125 CVE-2018-19566: A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to s A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
nvd
CVE-2018-19568MEDIUMCVSS 5.5≤ 9.282018-11-26
CVE-2018-19568 [MEDIUM] CWE-119 CVE-2018-19568: A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers a A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
nvd
CVE-2018-19567MEDIUMCVSS 5.5≤ 9.282018-11-26
CVE-2018-19567 [MEDIUM] CWE-119 CVE-2018-19567: A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able t A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
nvd
CVE-2015-3885MEDIUMCVSS 4.3≤ 7.002015-05-19
CVE-2015-3885 [MEDIUM] CWE-189 CVE-2015-3885: Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to ca Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
nvd