Libsixel Project Libsixel vulnerabilities
44 known vulnerabilities affecting libsixel_project/libsixel.
Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH16MEDIUM24
Vulnerabilities
Page 2 of 3
CVE-2019-20205HIGHCVSS 8.8v1.8.42020-01-02
CVE-2019-20205 [HIGH] CWE-190 CVE-2019-20205: libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
nvdosv
CVE-2019-20140HIGHCVSS 8.8v1.8.42019-12-30
CVE-2019-20140 [HIGH] CWE-787 CVE-2019-20140: An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.
nvdosv
CVE-2019-20094HIGHCVSS 8.8v1.8.42019-12-30
CVE-2019-20094 [HIGH] CWE-787 CVE-2019-20094: An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c.
nvdosv
CVE-2019-20056MEDIUMCVSS 6.5≥ 0, < 1.8.6-12019-12-29
CVE-2019-20056 [MEDIUM] CVE-2019-20056: stb_image
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.
osv
CVE-2019-20022MEDIUMCVSS 6.5fixed in 1.8.32019-12-27
CVE-2019-20022 [MEDIUM] CWE-672 CVE-2019-20022: An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8
An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
nvdosv
CVE-2019-20023MEDIUMCVSS 6.5fixed in 1.8.42019-12-27
CVE-2019-20023 [MEDIUM] CWE-401 CVE-2019-20023: A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
nvdosv
CVE-2019-20024MEDIUMCVSS 6.5fixed in 1.8.42019-12-27
CVE-2019-20024 [MEDIUM] CWE-787 CVE-2019-20024: A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before
A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
nvdosv
CVE-2019-19777HIGHCVSS 8.8v1.8.22019-12-13
CVE-2019-19777 [HIGH] CWE-125 CVE-2019-19777: stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-base
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
nvdosv
CVE-2019-19778HIGHCVSS 8.8v1.8.22019-12-13
CVE-2019-19778 [HIGH] CWE-125 CVE-2019-19778: An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function lo
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
nvdosv
CVE-2019-19637CRITICALCVSS 9.8v1.8.22019-12-08
CVE-2019-19637 [CRITICAL] CWE-190 CVE-2019-19637: An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.
nvdosv
CVE-2019-19636CRITICALCVSS 9.8v1.8.22019-12-08
CVE-2019-19636 [CRITICAL] CWE-190 CVE-2019-19636: An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.
nvdosv
CVE-2019-19635CRITICALCVSS 9.8v1.8.22019-12-08
CVE-2019-19635 [CRITICAL] CWE-787 CVE-2019-19635: An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function six
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.
nvdosv
CVE-2019-19638CRITICALCVSS 9.8v1.8.22019-12-08
CVE-2019-19638 [CRITICAL] CWE-190 CVE-2019-19638: An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function loa
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an integer overflow.
nvdosv
CVE-2019-11024MEDIUMCVSS 5.5v1.8.22019-04-08
CVE-2019-11024 [MEDIUM] CWE-674 CVE-2019-11024: The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
nvdosv
CVE-2019-3574HIGHCVSS 7.8v1.8.22019-01-02
CVE-2019-3574 [HIGH] CWE-125 CVE-2019-3574: In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file l
In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.
nvdosv
CVE-2019-3573MEDIUMCVSS 5.5v1.8.22019-01-02
CVE-2019-3573 [MEDIUM] CWE-835 CVE-2019-3573: In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fr
In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.
nvdosv
CVE-2018-19762HIGHCVSS 7.8v1.8.22018-11-30
CVE-2018-19762 [HIGH] CWE-787 CVE-2018-19762: There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8
There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a denial of service or possibly unspecified other impact.
nvdosv
CVE-2018-19757MEDIUMCVSS 6.5v1.8.22018-11-30
CVE-2018-19757 [MEDIUM] CWE-476 CVE-2018-19757: There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in li
There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.
nvdosv
CVE-2018-19756MEDIUMCVSS 5.5v1.8.22018-11-30
CVE-2018-19756 [MEDIUM] CWE-125 CVE-2018-19756: There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 t
There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of service.
nvdosv
CVE-2018-19761MEDIUMCVSS 5.5v1.8.22018-11-30
CVE-2018-19761 [MEDIUM] CWE-125 CVE-2018-19761: There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.
There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of service.
nvdosv