Libsixel Project Libsixel vulnerabilities

44 known vulnerabilities affecting libsixel_project/libsixel.

Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH16MEDIUM24

Vulnerabilities

Page 1 of 3
CVE-2025-61146MEDIUMCVSS 4.0fixed in 1.8.72026-02-23
CVE-2025-61146 [MEDIUM] CWE-401 CVE-2025-61146: saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub. saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
nvd
CVE-2025-9300MEDIUMCVSS 4.8≤ 1.10.32025-08-21
CVE-2025-9300 [MEDIUM] CWE-119 CVE-2025-9300: A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function s A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is
nvdosv
CVE-2022-29977MEDIUMCVSS 6.5v1.8.62022-05-11
CVE-2022-29977 [MEDIUM] CWE-617 CVE-2022-29977: There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixe There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
nvdosv
CVE-2022-29978MEDIUMCVSS 6.5v1.8.62022-05-11
CVE-2022-29978 [MEDIUM] CWE-682 CVE-2022-29978: There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2 There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
nvdosv
CVE-2022-27046HIGHCVSS 8.8v1.8.62022-04-08
CVE-2022-27046 [HIGH] CWE-416 CVE-2022-27046: libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388. libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
nvdosv
CVE-2021-40656HIGHCVSS 8.8fixed in 1.102022-04-08
CVE-2021-40656 [HIGH] CWE-787 CVE-2021-40656: libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867. libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
nvdosv
CVE-2021-41715HIGHCVSS 8.8v1.10.02022-04-08
CVE-2021-41715 [HIGH] CWE-416 CVE-2021-41715: libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379. libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
nvdosv
CVE-2022-27044HIGHCVSS 8.8v1.8.62022-04-08
CVE-2022-27044 [HIGH] CWE-787 CVE-2022-27044: libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876. libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
nvdosv
CVE-2022-27938MEDIUMCVSS 5.5v2.192022-03-26
CVE-2022-27938 [MEDIUM] CWE-617 CVE-2022-27938: stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
nvd
CVE-2021-46700MEDIUMCVSS 6.5v1.8.62022-02-19
CVE-2021-46700 [MEDIUM] CWE-415 CVE-2021-46700: In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in enc In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.
nvd
CVE-2021-45340MEDIUMCVSS 6.5≤ 1.10.32022-01-25
CVE-2021-45340 [MEDIUM] CWE-476 CVE-2021-45340: In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
nvdosv
CVE-2020-21547HIGHCVSS 8.8v1.8.22021-09-17
CVE-2020-21547 [HIGH] CWE-787 CVE-2020-21547: Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c. Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
nvdosv
CVE-2020-21548HIGHCVSS 8.8v1.8.32021-09-17
CVE-2020-21548 [HIGH] CWE-787 CVE-2020-21548: Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosix Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
nvdosv
CVE-2020-21049MEDIUMCVSS 6.5fixed in 1.8.52021-09-14
CVE-2020-21049 [MEDIUM] CWE-125 CVE-2020-21049: An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
nvdosv
CVE-2020-21050MEDIUMCVSS 6.5fixed in 1.8.32021-09-14
CVE-2020-21050 [MEDIUM] CWE-787 CVE-2020-21050: Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at from Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
nvdosv
CVE-2020-21048MEDIUMCVSS 6.5fixed in 1.8.42021-09-14
CVE-2020-21048 [MEDIUM] CVE-2020-21048: An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
nvdosv
CVE-2020-21677MEDIUMCVSS 6.5v1.8.42021-08-10
CVE-2020-21677 [MEDIUM] CWE-787 CVE-2020-21677: A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libs A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.
nvdosv
CVE-2020-36120HIGHCVSS 7.5v1.8.62021-04-14
CVE-2020-36120 [HIGH] CWE-120 CVE-2020-36120: Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS).
nvd
CVE-2020-19668MEDIUMCVSS 6.5v1.8.62020-11-20
CVE-2020-19668 [MEDIUM] CWE-125 CVE-2020-19668: Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.
nvdosv
CVE-2020-11721MEDIUMCVSS 6.5v1.8.62020-04-12
CVE-2020-11721 [MEDIUM] CWE-824 CVE-2020-11721: load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an inva load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.
nvdosv
Libsixel Project Libsixel vulnerabilities | cvebase