cbcvebase.

Freeimage Project Freeimage vulnerabilities

53 known vulnerabilities affecting freeimage_project/freeimage.

Total CVEs
53
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH21MEDIUM29LOW1

Vulnerabilities

Page 2 of 3
CVE-2020-21427P3HIGHCVSS 7.8v3.18.02023-08-22
CVE-2020-21427 [HIGH] CWE-120 CVE-2020-21427: Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 all Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
nvdosv
CVE-2020-21426P3HIGHCVSS 7.8v3.18.02023-08-22
CVE-2020-21426 [HIGH] CWE-120 CVE-2020-21426: Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allow Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
nvd
CVE-2020-21428P3HIGHCVSS 7.8v3.18.02023-08-22
CVE-2020-21428 [HIGH] CWE-120 CVE-2020-21428: Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
nvdosv
CVE-2024-28562P4MEDIUMCVSS 6.8v3.19.02024-03-20
CVE-2024-28562 [MEDIUM] CWE-787 CVE-2024-28562: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to e Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::copyIntoFrameBuffer() component when reading images in EXR format.
nvd
CVE-2021-40262P4MEDIUMCVSS 6.5fixed in 1.18.02023-08-22
CVE-2021-40262 [MEDIUM] CWE-787 CVE-2021-40262: A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in Plug A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp.
nvd
CVE-2019-12213P4MEDIUMCVSS 6.5v3.18.02019-05-20
CVE-2019-12213 [MEDIUM] CWE-674 CVE-2019-12213: When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp al When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.
nvdosv
CVE-2020-24294P4MEDIUMCVSS 6.5v3.19.02023-08-22
CVE-2020-24294 [MEDIUM] CWE-120 CVE-2020-24294: Buffer Overflow vulnerability in psdParser::UnpackRLE function in PSDParser.cpp in FreeImage 3.19.0 Buffer Overflow vulnerability in psdParser::UnpackRLE function in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to cuase a denial of service via opening of crafted psd file.
nvd
CVE-2025-65803P4MEDIUMCVSS 6.5≤ 3.18.02025-12-10
CVE-2025-65803 [MEDIUM] CWE-190 CVE-2025-65803: An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted PSD file.
nvd
CVE-2021-40264P4MEDIUMCVSS 6.5fixed in 1.18.02023-08-22
CVE-2021-40264 [MEDIUM] CWE-476 CVE-2021-40264: NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag functio NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp.
nvd
CVE-2020-22524P4MEDIUMCVSS 6.5v3.19.02023-08-22
CVE-2020-22524 [MEDIUM] CWE-120 CVE-2020-22524: Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows a Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.
nvdosv
CVE-2023-47997P4MEDIUMCVSS 6.5v3.18.02024-01-10
CVE-2023-47997 [MEDIUM] CWE-835 CVE-2023-47997: An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an in An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service.
nvd
CVE-2021-40266P4MEDIUMCVSS 6.5fixed in 1.18.02023-08-22
CVE-2021-40266 [MEDIUM] CWE-476 CVE-2021-40266: FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer deref FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.
nvd
CVE-2023-47995P4MEDIUMCVSS 6.5v3.18.02024-01-09
CVE-2023-47995 [MEDIUM] CWE-120 CVE-2023-47995: Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 allows attackers to cause a denial of service.
nvd
CVE-2023-47993P4MEDIUMCVSS 6.5v3.18.02024-01-09
CVE-2023-47993 [MEDIUM] CWE-125 CVE-2023-47993: A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.
nvd
CVE-2015-0852P4MEDIUMCVSS 5.0≤ 3.17.02015-09-29
CVE-2015-0852 [MEDIUM] CWE-189 CVE-2015-0852: Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.
nvdosv
CVE-2023-47996P4MEDIUMCVSS 6.5v3.18.02024-01-09
CVE-2023-47996 [MEDIUM] CWE-190 CVE-2023-47996: An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attacke An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a denial of service.
nvd
CVE-2015-3885P4MEDIUMCVSS 4.3≥ 0, < 3.15.4-62015-05-19
CVE-2015-3885 [MEDIUM] CVE-2015-3885: Integer overflow in the ljpeg_start function in dcraw 7 Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
osv
CVE-2024-28563P4MEDIUMCVSS 5.9v3.19.02024-03-20
CVE-2024-28563 [MEDIUM] CWE-121 CVE-2024-28563: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to c Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::DwaCompressor::Classifier::Classifier() function when reading images in EXR format.
nvd
CVE-2024-28564P4MEDIUMCVSS 6.2v3.19.02024-03-20
CVE-2024-28564 [MEDIUM] CWE-120 CVE-2024-28564: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to c Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::CharPtrIO::readChars() function when reading images in EXR format.
nvd
CVE-2024-28568P4MEDIUMCVSS 6.2v3.19.02024-03-20
CVE-2024-28568 [MEDIUM] CWE-121 CVE-2024-28568: Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to c Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the read_iptc_profile() function when reading images in TIFF format.
nvd
Freeimage Project Freeimage vulnerabilities | cvebase