CVE-2026-106118
- EPSS 0.6%
- Veröffentlicht 06.10.2026 17:59:02
- Zuletzt bearbeitet 06.10.2026 20:17:17
ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, tiled TIFF decoding allocates a destination buffer using TileWidth but TiffDecompressorsFactory.Create constructs T4, T6, and Modified Huffman decompressors using the full frame width. Tiff...
CVE-2026-106117
- EPSS 0.43%
- Veröffentlicht 06.10.2026 17:53:46
- Zuletzt bearbeitet 06.10.2026 20:03:40
ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded runs to BitWriterUtils.WriteBits without first checking the current row width. T4TiffCom...
CVE-2026-106116
- EPSS 0.37%
- Veröffentlicht 06.10.2026 17:51:36
- Zuletzt bearbeitet 06.10.2026 20:03:40
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the...
CVE-2026-106115
- EPSS 0.35%
- Veröffentlicht 06.10.2026 17:50:15
- Zuletzt bearbeitet 09.10.2026 02:16:57
ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyon...
CVE-2026-106114
- EPSS 0.37%
- Veröffentlicht 06.10.2026 17:48:41
- Zuletzt bearbeitet 06.10.2026 20:17:17
ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadC...
CVE-2026-106113
- EPSS 0.35%
- Veröffentlicht 06.10.2026 17:47:17
- Zuletzt bearbeitet 07.10.2026 17:16:47
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT70...
CVE-2026-106112
- EPSS 0.35%
- Veröffentlicht 06.10.2026 17:45:58
- Zuletzt bearbeitet 06.10.2026 20:03:40
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When De...
CVE-2026-106111
- EPSS 0.35%
- Veröffentlicht 06.10.2026 17:44:24
- Zuletzt bearbeitet 06.10.2026 20:03:40
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ExrBaseDecompressor.UndoZipCompression accepts a nonempty ZIP or ZIPS inflate result that is shorter than the EXR block's required size. ZipExrCompression.Decompress reconstructs the return...
CVE-2026-106110
- EPSS 0.35%
- Veröffentlicht 06.10.2026 17:42:02
- Zuletzt bearbeitet 09.10.2026 02:16:57
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 e...
CVE-2025-54575
- EPSS 0.38%
- Veröffentlicht 30.07.2025 19:55:16
- Zuletzt bearbeitet 15.04.2026 00:35:42
ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an inf...