Libvips

Libvips

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 17.04.2026 14:16:35
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such manipulation of the argument n leads to heap-based...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 27.02.2026 03:16:03
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires a local approach. T...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 27.02.2026 03:16:02
  • Zuletzt bearbeitet 02.03.2026 17:56:47

A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_band leads to out-of-bounds read. The attack needs to be perf...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 27.02.2026 03:16:02
  • Zuletzt bearbeitet 02.03.2026 17:58:30

A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to out-of-bounds read. The attack n...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 27.02.2026 02:16:20
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in heap-based buffer overflow. The attack must be initiat...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 25.02.2026 04:16:05
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 25.02.2026 03:16:07
  • Zuletzt bearbeitet 25.02.2026 20:56:00

A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack needs to be performe...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 25.02.2026 03:16:07
  • Zuletzt bearbeitet 25.02.2026 20:56:39

A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. Executing a manipulation can lead to memory corruption. T...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 22.02.2026 04:02:13
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on ...

  • EPSS 0.02%
  • Veröffentlicht 29.09.2025 22:15:36
  • Zuletzt bearbeitet 24.12.2025 15:16:01

libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips is compiled with support for PDF input via poppler, the pdfload operation is affected by a buffer read overflow when parsing the h...