cbcvebase.

Freeimage Project Freeimage vulnerabilities

53 known vulnerabilities affecting freeimage_project/freeimage.

Total CVEs
53
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH21MEDIUM29LOW1

Vulnerabilities

Page 1 of 3
CVE-2024-31570P3CRITICALCVSS 9.8≥ 3.4.0, ≤ 3.18.02024-09-19
CVE-2024-31570 [CRITICAL] CWE-787 CVE-2024-31570: libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cp libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.
nvd
CVE-2020-24292P3HIGHCVSS 8.8v3.19.02023-08-22
CVE-2020-24292 [HIGH] CWE-120 CVE-2020-24292: Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows r Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.
nvd
CVE-2025-70968P3CRITICALCVSS 9.8v3.18.02026-01-14
CVE-2025-70968 [CRITICAL] CWE-416 CVE-2025-70968: FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE(). FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
nvd
CVE-2020-24293P3HIGHCVSS 8.8v3.19.02023-08-22
CVE-2020-24293 [HIGH] CWE-120 CVE-2020-24293: Buffer Overflow vulnerability in psdThumbnail::Read in PSDParser.cpp in FreeImage 3.19.0 [r1859] all Buffer Overflow vulnerability in psdThumbnail::Read in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted psd file.
nvd
CVE-2020-24295P3HIGHCVSS 8.8v3.19.02023-08-22
CVE-2020-24295 [HIGH] CWE-120 CVE-2020-24295: Buffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in FreeImage 3.19.0 [r1859] allows r Buffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in FreeImage 3.19.0 [r1859] allows remote attackers to ru narbitrary code via use of crafted psd file.
nvd
CVE-2021-40263P3HIGHCVSS 8.8v1.18.02023-08-22
CVE-2021-40263 [HIGH] CWE-787 CVE-2021-40263: A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad function in PluginTIFF.cpp. A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad function in PluginTIFF.cpp.
nvd
CVE-2021-40265P3HIGHCVSS 8.8fixed in 1.18.02023-08-22
CVE-2021-40265 [HIGH] CWE-787 CVE-2021-40265: A heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp. A heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp.
nvd
CVE-2019-12211P3HIGHCVSS 7.5v3.18.02019-05-20
CVE-2019-12211 [HIGH] CWE-787 CVE-2019-12211: When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cp When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the copied data are not considered, resulting in a heap overflow.
nvdosv
CVE-2024-28578P3HIGHCVSS 8.4v3.19.02024-03-20
CVE-2024-28578 [HIGH] CWE-125 CVE-2024-28578: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to e Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in RAS format.
nvd
CVE-2016-5684P3HIGHCVSS 7.8v3.17.02017-01-06
CVE-2016-5684 [HIGH] CWE-787 CVE-2016-5684: An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of t An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.
nvdosv
CVE-2024-28566P3HIGHCVSS 8.4v3.19.02024-03-20
CVE-2024-28566 [HIGH] CWE-121 CVE-2024-28566: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to e Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format.
nvd
CVE-2024-28582P3HIGHCVSS 8.4v3.19.02024-03-20
CVE-2024-28582 [HIGH] CWE-121 CVE-2024-28582: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to e Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format.
nvd
CVE-2024-28581P3HIGHCVSS 8.4v3.19.02024-03-20
CVE-2024-28581 [HIGH] CWE-121 CVE-2024-28581: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to e Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format.
nvd
CVE-2024-28580P3HIGHCVSS 8.4v3.19.02024-03-20
CVE-2024-28580 [HIGH] CWE-121 CVE-2024-28580: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to e Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format.
nvd
CVE-2023-47994P3HIGHCVSS 8.8v3.18.02024-01-09
CVE-2023-47994 [HIGH] CWE-190 CVE-2023-47994: An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.
nvd
CVE-2019-12212P3HIGHCVSS 7.5v3.18.02019-05-20
CVE-2019-12212 [HIGH] CWE-674 CVE-2019-12212: When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeated When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file.
nvd
CVE-2019-12214P3HIGHCVSS 7.5v3.18.02019-05-20
CVE-2019-12214 [HIGH] CWE-125 CVE-2019-12214: In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j2k.c. The value of l_N_ppm comes from the file read in, and the code does not consider that l_N_ppm may be greater than the size of p_header_data.
nvd
CVE-2024-28583P3HIGHCVSS 7.8v3.19.02024-03-20
CVE-2024-28583 [HIGH] CWE-120 CVE-2024-28583: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to e Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the readLine() function when reading images in XPM format.
nvd
CVE-2023-47992P3HIGHCVSS 8.8v3.18.02024-01-09
CVE-2023-47992 [HIGH] CWE-190 CVE-2023-47992: An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows att An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.
nvd
CVE-2024-28569P3HIGHCVSS 7.8v3.19.02024-03-20
CVE-2024-28569 [HIGH] CWE-120 CVE-2024-28569: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to e Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in EXR format.
nvd
Freeimage Project Freeimage vulnerabilities | cvebase