CVE-2026-88360
- EPSS 0.14%
- Veröffentlicht 24.09.2026 14:18:18
- Zuletzt bearbeitet 06.10.2026 18:16:57
libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-based loader can expose pixel data at an address that is not properly aligned for ...
CVE-2026-70654
- EPSS -
- Veröffentlicht 20.08.2026 21:17:08
- Zuletzt bearbeitet 18.09.2026 20:09:01
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_re...
CVE-2026-70653
- EPSS -
- Veröffentlicht 20.08.2026 21:17:08
- Zuletzt bearbeitet 18.09.2026 20:09:01
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1]...
- EPSS -
- Veröffentlicht 20.08.2026 21:17:08
- Zuletzt bearbeitet 18.09.2026 20:09:01
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pip...
CVE-2026-70651
- EPSS -
- Veröffentlicht 20.08.2026 21:17:08
- Zuletzt bearbeitet 18.09.2026 20:09:01
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsF...
CVE-2026-69242
- EPSS -
- Veröffentlicht 20.08.2026 21:17:07
- Zuletzt bearbeitet 18.09.2026 20:09:01
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_i...
CVE-2026-35591
- EPSS 0.17%
- Veröffentlicht 20.07.2026 16:24:50
- Zuletzt bearbeitet 19.08.2026 19:10:32
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, lead...
CVE-2026-35590
- EPSS 0.15%
- Veröffentlicht 20.07.2026 16:23:33
- Zuletzt bearbeitet 19.08.2026 19:17:06
libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer d...
CVE-2026-33328
- EPSS 0.15%
- Veröffentlicht 20.07.2026 16:22:22
- Zuletzt bearbeitet 19.08.2026 19:19:16
libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in versi...
CVE-2026-33327
- EPSS 0.17%
- Veröffentlicht 20.07.2026 16:21:16
- Zuletzt bearbeitet 19.08.2026 19:24:19
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow...