Freeimage Project Freeimage vulnerabilities

53 known vulnerabilities affecting freeimage_project/freeimage.

Total CVEs
53
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH21MEDIUM29LOW1

Vulnerabilities

Page 3 of 3
CVE-2021-40266MEDIUMCVSS 6.5fixed in 1.18.02023-08-22
CVE-2021-40266 [MEDIUM] CWE-476 CVE-2021-40266: FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer deref FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.
nvd
CVE-2021-40262MEDIUMCVSS 6.5fixed in 1.18.02023-08-22
CVE-2021-40262 [MEDIUM] CWE-787 CVE-2021-40262: A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in Plug A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp.
nvd
CVE-2020-22524MEDIUMCVSS 6.5v3.19.02023-08-22
CVE-2020-22524 [MEDIUM] CWE-120 CVE-2020-22524: Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows a Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.
nvdosv
CVE-2021-40264MEDIUMCVSS 6.5fixed in 1.18.02023-08-22
CVE-2021-40264 [MEDIUM] CWE-476 CVE-2021-40264: NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag functio NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp.
nvd
CVE-2020-24294MEDIUMCVSS 6.5v3.19.02023-08-22
CVE-2020-24294 [MEDIUM] CWE-120 CVE-2020-24294: Buffer Overflow vulnerability in psdParser::UnpackRLE function in PSDParser.cpp in FreeImage 3.19.0 Buffer Overflow vulnerability in psdParser::UnpackRLE function in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to cuase a denial of service via opening of crafted psd file.
nvd
CVE-2021-33367MEDIUMCVSS 5.5v3.18.02023-02-22
CVE-2021-33367 [MEDIUM] CWE-125 CVE-2021-33367: Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of service via Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of service via a crafted JXR file.
nvd
CVE-2019-12214HIGHCVSS 7.5v3.18.02019-05-20
CVE-2019-12214 [HIGH] CWE-125 CVE-2019-12214: In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j2k.c. The value of l_N_ppm comes from the file read in, and the code does not consider that l_N_ppm may be greater than the size of p_header_data.
nvd
CVE-2019-12212HIGHCVSS 7.5v3.18.02019-05-20
CVE-2019-12212 [HIGH] CWE-674 CVE-2019-12212: When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeated When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file.
nvd
CVE-2019-12211HIGHCVSS 7.5v3.18.02019-05-20
CVE-2019-12211 [HIGH] CWE-787 CVE-2019-12211: When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cp When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the copied data are not considered, resulting in a heap overflow.
nvdosv
CVE-2019-12213MEDIUMCVSS 6.5v3.18.02019-05-20
CVE-2019-12213 [MEDIUM] CWE-674 CVE-2019-12213: When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp al When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.
nvdosv
CVE-2016-5684HIGHCVSS 7.8v3.17.02017-01-06
CVE-2016-5684 [HIGH] CWE-787 CVE-2016-5684: An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of t An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.
nvdosv
CVE-2015-0852MEDIUMCVSS 5.0≤ 3.17.02015-09-29
CVE-2015-0852 [MEDIUM] CWE-189 CVE-2015-0852: Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.
nvdosv
CVE-2015-3885MEDIUMCVSS 4.3≥ 0, < 3.15.4-62015-05-19
CVE-2015-3885 [MEDIUM] CVE-2015-3885: Integer overflow in the ljpeg_start function in dcraw 7 Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
osv
Freeimage Project Freeimage vulnerabilities | cvebase