Debian Imlib2 vulnerabilities
21 known vulnerabilities affecting debian/imlib2.
Total CVEs
21
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH10MEDIUM6
Vulnerabilities
Page 1 of 2
CVE-2016-4024P3CRITICALCVSS 9.8fixed in imlib2 1.4.8-1 (bookworm)2016
CVE-2016-4024 [CRITICAL] CVE-2016-4024: imlib2 - Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attack...
Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.
Scope: local
bookworm: resolved (fixed in 1.4.8-1)
bullseye: resolved (fixed in 1.4.8-1)
forky: resolved (fixed in 1.4.8-1)
sid: resolved (fixed in 1.4.8-1)
trixi
debian
CVE-2008-2426P3MEDIUMCVSS 9.3fixed in imlib2 1.4.0-1.1 (bookworm)2008
CVE-2008-2426 [CRITICAL] CVE-2008-2426: imlib2 - Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-a...
Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loader_pnm.c; or (2) a crafted XPM image, related to the load function in src/modules/loader_xp
debian
CVE-2020-12761P3CRITICALCVSS 9.1fixed in imlib2 1.6.1-2 (bookworm)2020
CVE-2020-12761 [CRITICAL] CVE-2020-12761: imlib2 - modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resul...
modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.
Scope: local
bookworm: resolved (fixed in 1.6.1-2)
bullseye: resolved (fixed in 1.6.1-2)
forky: resolved (fixed in 1.6.1-2)
sid: resolved (fixed in 1.6.1-2)
trixie: resolved (fixed
debian
CVE-2024-25448P3HIGHCVSS 8.8fixed in imlib2 1.10.0-2 (bookworm)2024
CVE-2024-25448 [HIGH] CVE-2024-25448: imlib2 - An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows at...
An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
Scope: local
bookworm: resolved (fixed in 1.10.0-2)
bullseye: resolved (fixed in 1.7.1-2+deb11u1)
forky: resolved (fixed in 1.10.0-2)
sid: resolved (fixed in 1.10.0-2)
trixie: resolved (fixed in 1.10.0-2)
debian
CVE-2024-25447P3HIGHCVSS 8.8fixed in imlib2 1.10.0-2 (bookworm)2024
CVE-2024-25447 [HIGH] CVE-2024-25447: imlib2 - An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 all...
An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
Scope: local
bookworm: resolved (fixed in 1.10.0-2)
bullseye: resolved (fixed in 1.7.1-2+deb11u1)
forky: resolved (fixed in 1.10.0-2)
sid: resolved (fixed in 1.10.0-2)
trixie: resolved (fixed in 1.10.0-2)
debian
CVE-2008-6079P3CRITICALCVSS 10.0fixed in imlib2 1.4.2-1 (bookworm)2008
CVE-2008-6079 [CRITICAL] CVE-2008-6079: imlib2 - imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified im...
imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related to "several heap and stack based buffer overflows - partly due to integer overflows."
Scope: local
bookworm: resolved (fixed in 1.4.2-1)
bullseye: resolved (fixed in 1.4.2-1)
forky: resol
debian
CVE-2024-25450P3HIGHCVSS 8.8fixed in imlib2 1.10.0-2 (bookworm)2024
CVE-2024-25450 [HIGH] CVE-2024-25450: imlib2 - imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init...
imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().
Scope: local
bookworm: resolved (fixed in 1.10.0-2)
bullseye: resolved (fixed in 1.7.1-2+deb11u1)
forky: resolved (fixed in 1.10.0-2)
sid: resolved (fixed in 1.10.0-2)
trixie: resolved (fixed in 1.10.0-2)
debian
CVE-2008-5187P3CRITICALCVSS 9.3fixed in imlib2 1.4.0-1.2 (bookworm)2008
CVE-2008-5187 [CRITICAL] CVE-2008-5187: imlib2 - The load function in the XPM loader for imlib2 1.4.2, and possibly other version...
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
Scope: local
bookworm: resolved (fixed in 1.4.0-
debian
CVE-2016-3994P4HIGHCVSS 8.2fixed in imlib2 1.4.8-1 (bookworm)2016
CVE-2016-3994 [HIGH] CVE-2016-3994: imlib2 - The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial ...
The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 1.4.8-1)
bullseye: resolved (fixed in 1.4.8-1)
forky: resolved (fixed in 1.4.8-1)
sid: resolved (fixed in 1.4.8-1)
trixie: reso
debian
CVE-2014-9762P4HIGHCVSS 7.5fixed in imlib2 1.4.7-1 (bookworm)2014
CVE-2014-9762 [HIGH] CVE-2014-9762: imlib2 - imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmen...
imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a colormap.
Scope: local
bookworm: resolved (fixed in 1.4.7-1)
bullseye: resolved (fixed in 1.4.7-1)
forky: resolved (fixed in 1.4.7-1)
sid: resolved (fixed in 1.4.7-1)
trixie: resolved (fixed in 1.4.7-1)
debian
CVE-2016-3993P4HIGHCVSS 7.5fixed in imlib2 1.4.8-1 (bookworm)2016
CVE-2016-3993 [HIGH] CVE-2016-3993: imlib2 - Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 ...
Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted coordinates.
Scope: local
bookworm: resolved (fixed in 1.4.8-1)
bullseye: resolved (fixed in 1.4.8-1)
forky: resolved (fixed in 1.4.8-1)
sid: resolved (fixed in 1.4.8-1)
debian
CVE-2014-9764P4HIGHCVSS 7.5fixed in imlib2 1.4.7-1 (bookworm)2014
CVE-2014-9764 [HIGH] CVE-2014-9764: imlib2 - imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmen...
imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file.
Scope: local
bookworm: resolved (fixed in 1.4.7-1)
bullseye: resolved (fixed in 1.4.7-1)
forky: resolved (fixed in 1.4.7-1)
sid: resolved (fixed in 1.4.7-1)
trixie: resolved (fixed in 1.4.7-1)
debian
CVE-2014-9771P4HIGHCVSS 7.5fixed in imlib2 1.4.7-1 (bookworm)2014
CVE-2014-9771 [HIGH] CVE-2014-9771: imlib2 - Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denia...
Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted image, which triggers an invalid read operation.
Scope: local
bookworm: resolved (fixed in 1.4.7-1)
bullseye: resolved (fixed in 1.4.7-1)
forky: resolved (fixed in 1.4.7-1)
sid: resolved (fixed in 1.4.7-1)
trixie: resolved
debian
CVE-2004-1026P4CRITICALCVSS 10.0fixed in imlib2 1.1.2-2.1 (bookworm)2004
CVE-2004-1026 [CRITICAL] CVE-2004-1026: imlib2 - Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, wh...
Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
Scope: local
bookworm: resolved (fixed in 1.1.2-2.1)
bullseye: resolved (fixed in 1.1.2-2.1)
forky: resolved (f
debian
CVE-2011-5326P4HIGHCVSS 7.5fixed in imlib2 1.4.8-1 (bookworm)2011
CVE-2011-5326 [HIGH] CVE-2011-5326: imlib2 - imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide...
imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.
Scope: local
bookworm: resolved (fixed in 1.4.8-1)
bullseye: resolved (fixed in 1.4.8-1)
forky: resolved (fixed in 1.4.8-1)
sid: resolved (fixed in 1.4.8-1)
trixie: resolved (fixed in 1.4.8-1)
debian
CVE-2014-9763P4HIGHCVSS 7.5fixed in imlib2 1.4.7-1 (bookworm)2014
CVE-2014-9763 [HIGH] CVE-2014-9763: imlib2 - imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide...
imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.
Scope: local
bookworm: resolved (fixed in 1.4.7-1)
bullseye: resolved (fixed in 1.4.7-1)
forky: resolved (fixed in 1.4.7-1)
sid: resolved (fixed in 1.4.7-1)
trixie: resolved (fixed in 1.4.7-1)
debian
CVE-2004-0802P4MEDIUMCVSS 5.1fixed in imlib2 1.1.0-12.4 (bookworm)2004
CVE-2004-0802 [MEDIUM] CVE-2004-0802: imlib2 - Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers...
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
Scope: local
bookworm: resolved (fixed in 1.1.0-12.4)
bullseye: resolved (fixed in 1.1.0-12.4)
forky: resolved (fixed in 1.1.0-12.4)
sid: resolved (fixed in 1.1.0-12.4)
trixie: reso
debian
CVE-2006-4806P4MEDIUMCVSS 5.1fixed in imlib2 1.3.0.0debian1-3 (bookworm)2006
CVE-2006-4806 [MEDIUM] CVE-2006-4806: imlib2 - Multiple integer overflows in imlib2 allow user-assisted remote attackers to cau...
Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.
Scope: local
bookworm: resolved (fixed in 1.3.0.0debian1-3)
bullseye: re
debian
CVE-2006-4809P4MEDIUMCVSS 5.1fixed in imlib2 1.3.0.0debian1-3 (bookworm)2006
CVE-2006-4809 [MEDIUM] CVE-2006-4809: imlib2 - Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly...
Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM image.
Scope: local
bookworm: resolved (fixed in 1.3.0.0debian1-3)
bullseye: resolved (fixed in 1.3.0.0debian1-3)
forky: resolved (fixed in 1.3
debian
CVE-2006-4808P4MEDIUMCVSS 2.6fixed in imlib2 1.3.0.0debian1-3 (bookworm)2006
CVE-2006-4808 [LOW] CVE-2006-4808: imlib2 - Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly ...
Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image.
Scope: local
bookworm: resolved (fixed in 1.3.0.0debian1-3)
bullseye: resolved (fixed in 1.3.0.0debian1-3)
forky: resolved (fixed in 1.3.0.0
debian
1 / 2Next →