CVE-2025-59933
- EPSS 0.02%
- Published 29.09.2025 22:15:36
- Last modified 02.10.2025 19:12:42
libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips is compiled with support for PDF input via poppler, the pdfload operation is affected by a buffer read overflow when parsing the h...
CVE-2025-29769
- EPSS 0.04%
- Published 07.04.2025 20:15:21
- Last modified 09.10.2025 13:41:29
libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when it was not possible to determine the colour interpretation, known intern...
CVE-2023-40032
- EPSS 0.09%
- Published 11.09.2023 19:15:43
- Last modified 21.04.2025 13:45:44
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips v...
CVE-2021-27847
- EPSS 0.11%
- Published 15.07.2021 16:15:09
- Last modified 21.11.2024 05:58:37
Division-By-Zero vulnerability in Libvips 8.10.5 in the function vips_eye_point, eye.c#L83, and function vips_mask_point, mask.c#L85.
CVE-2020-20739
- EPSS 0.2%
- Published 20.11.2020 19:15:11
- Last modified 21.11.2024 05:12:15
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
CVE-2019-17534
- EPSS 0.99%
- Published 13.10.2019 02:15:12
- Last modified 21.11.2024 04:32:28
vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, leading to a use-after-free.
CVE-2019-6976
- EPSS 0.48%
- Published 26.01.2019 23:29:00
- Last modified 21.11.2024 04:47:20
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through th...
CVE-2018-7998
- EPSS 0.32%
- Published 09.03.2018 19:29:01
- Last modified 21.11.2024 04:13:03
In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted ...