CVE-2025-43964
- EPSS 0.04%
- Veröffentlicht 20.04.2025 00:00:00
- Zuletzt bearbeitet 08.05.2025 16:54:54
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
CVE-2025-43963
- EPSS 0.03%
- Veröffentlicht 20.04.2025 00:00:00
- Zuletzt bearbeitet 08.05.2025 16:54:47
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.
CVE-2025-43962
- EPSS 0.03%
- Veröffentlicht 20.04.2025 00:00:00
- Zuletzt bearbeitet 08.05.2025 16:54:40
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.
CVE-2025-43961
- EPSS 0.03%
- Veröffentlicht 20.04.2025 00:00:00
- Zuletzt bearbeitet 08.05.2025 16:54:14
In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.
CVE-2020-22628
- EPSS 0.06%
- Veröffentlicht 22.08.2023 19:16:19
- Zuletzt bearbeitet 05.05.2025 14:12:26
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
CVE-2023-1729
- EPSS 0.06%
- Veröffentlicht 15.05.2023 22:15:10
- Zuletzt bearbeitet 20.03.2025 17:01:00
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
CVE-2021-32142
- EPSS 0.02%
- Veröffentlicht 17.02.2023 18:15:10
- Zuletzt bearbeitet 19.03.2025 15:15:35
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
CVE-2020-35535
- EPSS 0.05%
- Veröffentlicht 01.09.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:27:31
In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when processing srf files.
CVE-2020-35534
- EPSS 0.16%
- Veröffentlicht 01.09.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:27:31
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.
CVE-2020-35533
- EPSS 0.02%
- Veröffentlicht 01.09.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:27:30
In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decoders\dng.cpp) when reading data from the image file.