CVE-2026-44637
- EPSS 0.01%
- Veröffentlicht 14.05.2026 20:02:32
- Zuletzt bearbeitet 15.05.2026 17:55:03
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in sixel_decode_raw_impl. context->po...
CVE-2026-44636
- EPSS 0.01%
- Veröffentlicht 14.05.2026 20:01:27
- Zuletzt bearbeitet 16.05.2026 01:16:16
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode entry point ...
CVE-2026-44638
- EPSS 0.01%
- Veröffentlicht 14.05.2026 19:59:29
- Zuletzt bearbeitet 15.05.2026 17:54:09
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointer dereference whenever the allocation fails. The ch...
CVE-2026-33023
- EPSS 0.01%
- Veröffentlicht 14.04.2026 22:05:31
- Zuletzt bearbeitet 23.04.2026 14:46:46
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf() in loader.c. The cleanup path ma...
CVE-2026-33021
- EPSS 0.02%
- Veröffentlicht 14.04.2026 21:57:22
- Zuletzt bearbeitet 23.04.2026 14:23:26
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the caller-owned pixel buffer pointer dir...
CVE-2026-33020
- EPSS 0.02%
- Veröffentlicht 14.04.2026 21:53:00
- Zuletzt bearbeitet 23.04.2026 14:47:18
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointe...
CVE-2026-33019
- EPSS 0.01%
- Veröffentlicht 14.04.2026 21:49:25
- Zuletzt bearbeitet 23.04.2026 14:47:42
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT...
- EPSS 0.02%
- Veröffentlicht 14.04.2026 21:45:42
- Zuletzt bearbeitet 23.04.2026 14:48:09
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t object is reused across all frames o...
- EPSS 0.02%
- Veröffentlicht 23.02.2026 00:00:00
- Zuletzt bearbeitet 23.04.2026 15:15:58
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
CVE-2025-9300
- EPSS 0.06%
- Veröffentlicht 21.08.2025 13:02:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack mus...