Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cimg

First CVE: Mar 1, 2018Active for: 8 yearsTotal CVEs: 14
48.6
VTI Score
High

Cimg is a specialized image processing and manipulation library that, despite a narrow product scope, ranks among the more prominent software components in the vulnerability landscape owing to its role in graphics workflows and wide downstream embedding. The vendor's vulnerability exposure clusters in memory-safety and resource-management weakness classes—including out-of-bounds reads and writes, heap-based buffer overflows, double-free conditions, and resource-allocation failures—that are characteristic of C-based image codecs and parsers handling untrusted image data. Defenders tracking this library should inventory downstream products that link it and treat image-processing pipelines as a vector for remote code execution; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cimg over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2018
8 years ago
Most Recent CVE
Mar 15, 2024
861 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-1010174CRITICAL
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image f
Jul 25, 20199.832NONO
CVE-2019-13568HIGH
CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a malformed BMP image.
Jul 31, 20198.826NONO
CVE-2020-25693HIGH
A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed b
Dec 3, 20208.125NONO
CVE-2018-7638HIGH
An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th
Mar 2, 20187.825NONO
CVE-2018-7588HIGH
An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image.
Mar 1, 20187.825NONO
CVE-2018-7641HIGH
An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th
Mar 2, 20187.824NONO
CVE-2018-7640HIGH
An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th
Mar 2, 20187.824NONO
CVE-2018-7639HIGH
An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th
Mar 2, 20187.824NONO
CVE-2018-7637HIGH
An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th
Mar 2, 20187.824NONO
CVE-2018-7589HIGH
An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image.
Mar 1, 20187.824NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
86%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (71.4%)
Network4 (28.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (7.1%)
Unknown0 (0.0%)
Required13 (92.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cimg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cimg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cimg's Products

View all 3 CNAs →

Top CWEs