VYPR

libvips

by Debian

CVEs (4)

  • CVE-2026-35591Jul 21, 2026
    risk 0.00cvss epss

    libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer…

  • CVE-2026-35590Jul 21, 2026
    risk 0.00cvss epss

    libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This…

  • CVE-2026-33328Jul 21, 2026
    risk 0.00cvss epss

    libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.

  • CVE-2026-33327Jul 21, 2026
    risk 0.00cvss epss

    libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in…