CVE-2026-3284
- EPSS 0.02%
- Veröffentlicht 27.02.2026 03:16:03
- Zuletzt bearbeitet 02.03.2026 16:30:59
A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires a local approach. T...
CVE-2026-3282
- EPSS 0.01%
- Veröffentlicht 27.02.2026 03:16:02
- Zuletzt bearbeitet 02.03.2026 17:58:30
A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to out-of-bounds read. The attack n...
CVE-2026-3283
- EPSS 0.01%
- Veröffentlicht 27.02.2026 03:16:02
- Zuletzt bearbeitet 02.03.2026 17:56:47
A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_band leads to out-of-bounds read. The attack needs to be perf...
CVE-2026-3281
- EPSS 0.01%
- Veröffentlicht 27.02.2026 02:16:20
- Zuletzt bearbeitet 02.03.2026 17:59:24
A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in heap-based buffer overflow. The attack must be initiat...
CVE-2026-3147
- EPSS 0.02%
- Veröffentlicht 25.02.2026 04:16:05
- Zuletzt bearbeitet 25.02.2026 20:54:52
A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit ...
CVE-2026-3145
- EPSS 0.02%
- Veröffentlicht 25.02.2026 03:16:07
- Zuletzt bearbeitet 25.02.2026 20:56:39
A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. Executing a manipulation can lead to memory corruption. T...
CVE-2026-3146
- EPSS 0.01%
- Veröffentlicht 25.02.2026 03:16:07
- Zuletzt bearbeitet 25.02.2026 20:56:00
A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack needs to be performe...
- EPSS 0.02%
- Veröffentlicht 22.02.2026 04:02:13
- Zuletzt bearbeitet 24.02.2026 16:15:51
A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on ...
CVE-2025-59933
- EPSS 0.02%
- Veröffentlicht 29.09.2025 22:15:36
- Zuletzt bearbeitet 24.12.2025 15:16:01
libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips is compiled with support for PDF input via poppler, the pdfload operation is affected by a buffer read overflow when parsing the h...
CVE-2025-29769
- EPSS 0.1%
- Veröffentlicht 07.04.2025 20:15:21
- Zuletzt bearbeitet 09.10.2025 13:41:29
libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when it was not possible to determine the colour interpretation, known intern...