VYPR

Pillow

by Python (programming language)

pypi: pillow

Source repositories

CVEs (73)

  • CVE-2022-30595CriMay 25, 2022
    risk 0.57cvss 9.8epss 0.02

    libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.

  • CVE-2022-22817CriJan 10, 2022
    risk 0.57cvss 9.8epss 0.03

    PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.

  • CVE-2021-34552CriJul 13, 2021
    risk 0.57cvss 9.8epss 0.03

    Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.

  • CVE-2021-25289CriMar 19, 2021
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.

  • CVE-2020-5312CriJan 3, 2020
    risk 0.57cvss 9.8epss 0.04

    libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

  • CVE-2020-5311CriJan 3, 2020
    risk 0.57cvss 9.8epss 0.04

    libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.

  • CVE-2016-4009CriApr 13, 2016
    risk 0.57cvss 9.8epss 0.08

    Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.

  • CVE-2026-54058CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.00

    Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as…

  • CVE-2022-24303CriMar 28, 2022
    risk 0.52cvss 9.1epss 0.03

    Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

  • CVE-2021-25288CriJun 2, 2021
    risk 0.52cvss 9.1epss 0.02

    An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.

  • CVE-2021-25287CriJun 2, 2021
    risk 0.52cvss 9.1epss 0.03

    An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.

  • CVE-2016-9190HigNov 4, 2016
    risk 0.51cvss 7.8epss 0.02

    Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

  • CVE-2020-35654HigJan 12, 2021
    risk 0.50cvss 8.8epss 0.02

    In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.

  • CVE-2020-5310HigJan 3, 2020
    risk 0.50cvss 8.8epss 0.02

    libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.

  • CVE-2026-59197HigJul 14, 2026
    risk 0.46cvss 8.2epss 0.00

    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size…

  • CVE-2023-50447HigJan 19, 2024
    risk 0.46cvss 8.1epss 0.02

    Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

  • CVE-2020-11538HigJun 25, 2020
    risk 0.46cvss 8.1epss 0.03

    In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

  • CVE-2026-42311HigMay 9, 2026
    risk 0.44cvss 7.8epss 0.00

    Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

  • CVE-2020-10379HigJun 25, 2020
    risk 0.44cvss 7.8epss 0.01

    In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.

  • CVE-2026-59200HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to…

Page 1 of 4