VYPR
Vendor

Libvips

Products
2
CVEs
29
Across products
29
Status
Private

Products

2

Recent CVEs

29
View all 29 CVEs →
  • CVE-2017-17514HigDec 14, 2017
    risk 0.57cvss 8.8epss 0.02

    boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does…

  • CVE-2019-17534HigOct 13, 2019
    risk 0.50cvss 8.8epss 0.02

    vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, leading to a use-after-free.

  • CVE-2018-7998HigMar 9, 2018
    risk 0.49cvss 7.5epss 0.02

    In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file. This occurs…

  • CVE-2026-69242HigAug 20, 2026
    risk 0.48cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting…

  • CVE-2026-35591HigJul 20, 2026
    risk 0.44cvss 7.8epss 0.00

    libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer…

  • CVE-2026-33327HigJul 20, 2026
    risk 0.44cvss 7.8epss 0.00

    libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in…

  • CVE-2021-27847MedJul 15, 2021
    risk 0.42cvss 6.5epss 0.01

    Division-By-Zero vulnerability in Libvips 8.10.5 in the function vips_eye_point, eye.c#L83, and function vips_mask_point, mask.c#L85.

  • CVE-2026-70651MedAug 20, 2026
    risk 0.38cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The…

  • CVE-2020-20739MedNov 20, 2020
    risk 0.35cvss 5.3epss 0.02

    im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.

  • CVE-2026-6491MedApr 17, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such manipulation of the argument n leads to heap-based buffer overflow. An attack…

  • CVE-2026-70654MedAug 20, 2026
    risk 0.31cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in…

  • CVE-2026-35590MedJul 20, 2026
    risk 0.29cvss 5.5epss 0.00

    libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This…

  • CVE-2026-33328MedJul 20, 2026
    risk 0.29cvss 5.5epss 0.00

    libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.

  • CVE-2019-6976MedJan 26, 2019
    risk 0.28cvss 5.3epss 0.02

    libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

  • CVE-2026-3281MedFeb 27, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in heap-based buffer overflow. The attack must be initiated from a local position. The…

  • CVE-2026-3147MedFeb 25, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been made public and…

  • CVE-2026-70653MedAug 20, 2026
    risk 0.24cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel…

  • CVE-2026-3284LowFeb 27, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires a local approach. The exploit has been made…

  • CVE-2026-2913LowFeb 22, 2026
    risk 0.09cvss 2.5epss 0.00

    A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The attack's…

  • CVE-2026-70652LowAug 20, 2026
    risk 0.06cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming…