Python Pillow vulnerabilities

58 known vulnerabilities affecting python/pillow.

Total CVEs
58
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL11HIGH26MEDIUM20LOW1

Vulnerabilities

Page 3 of 3
CVE-2020-5311CRITICALCVSS 9.8fixed in 6.2.22020-01-03
CVE-2020-5311 [CRITICAL] CWE-120 CVE-2020-5311: libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
ghsanvdosv
CVE-2020-5312CRITICALCVSS 9.8fixed in 6.2.22020-01-03
CVE-2020-5312 [CRITICAL] CWE-120 CVE-2020-5312: libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
ghsanvdosv
CVE-2020-5313HIGHCVSS 7.1fixed in 6.2.22020-01-03
CVE-2020-5313 [HIGH] CWE-125 CVE-2020-5313: libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
ghsanvdosv
CVE-2020-5310HIGHCVSS 8.8fixed in 6.2.22020-01-03
CVE-2020-5310 [HIGH] CWE-190 CVE-2020-5310: libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to real libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
ghsanvdosv
CVE-2019-16865HIGHCVSS 7.5fixed in 6.2.02019-10-04
CVE-2019-16865 [HIGH] CWE-770 CVE-2019-16865: An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
ghsanvdosv
CVE-2016-3076MEDIUMCVSS 5.5v2.5.0v2.5.1+12 more2017-04-24
CVE-2016-3076 [MEDIUM] CWE-119 CVE-2016-3076: Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows rem Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
ghsanvdosv
CVE-2016-9190HIGHCVSS 7.8≤ 3.3.12016-11-04
CVE-2016-9190 [HIGH] CWE-284 CVE-2016-9190: Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "craft Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
ghsanvdosv
CVE-2016-9189MEDIUMCVSS 5.5≤ 3.3.12016-11-04
CVE-2016-9189 [MEDIUM] CWE-190 CVE-2016-9189: Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
ghsanvdosv
CVE-2016-4009CRITICALCVSS 9.8≤ 3.1.02016-04-13
CVE-2016-4009 [CRITICAL] CWE-119 CVE-2016-4009: Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.
ghsanvdosv
CVE-2016-2533MEDIUMCVSS 6.5≤ 3.1.02016-04-13
CVE-2016-2533 [MEDIUM] CWE-119 CVE-2016-2533: Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Im Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.
ghsanvdosv
CVE-2016-0775MEDIUMCVSS 6.5≤ 3.1.02016-04-13
CVE-2016-0775 [MEDIUM] CWE-119 CVE-2016-0775: Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 al Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
ghsanvdosv
CVE-2016-0740MEDIUMCVSS 6.5≤ 3.1.02016-04-13
CVE-2016-0740 [MEDIUM] CWE-119 CVE-2016-0740: Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1 Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
ghsanvdosv
CVE-2014-3598MEDIUMCVSS 5.0≤ 2.5.22015-05-01
CVE-2014-3598 [MEDIUM] CWE-399 CVE-2014-3598: The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of ser The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.
ghsanvdosv
CVE-2014-9601MEDIUMCVSS 5.0≤ 2.6.22015-01-16
CVE-2014-9601 [MEDIUM] CWE-20 CVE-2014-9601: Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
ghsanvdosv
CVE-2014-3589MEDIUMCVSS 5.0≤ 2.3.1v2.3.0+3 more2014-08-25
CVE-2014-3589 [MEDIUM] CWE-20 CVE-2014-3589: PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5. PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
ghsanvdosv
CVE-2014-3007CRITICALCVSS 10.0v2.3.02014-04-27
CVE-2014-3007 [CRITICAL] CVE-2014-3007: Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.
ghsanvdosv
CVE-2014-1932MEDIUMCVSS 4.4≤ 2.3.02014-04-17
CVE-2014-1932 [MEDIUM] CWE-59 CVE-2014-1932: The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3 The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sens
ghsanvdosv
CVE-2014-1933LOWCVSS 2.1≤ 2.3.02014-04-17
CVE-2014-1933 [LOW] CWE-264 CVE-2014-1933: The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
ghsanvdosv