Cimg is a specialized image processing and manipulation library that, despite a narrow product scope, ranks among the more prominent software components in the vulnerability landscape owing to its role in graphics workflows and wide downstream embedding. The vendor's vulnerability exposure clusters in memory-safety and resource-management weakness classes—including out-of-bounds reads and writes, heap-based buffer overflows, double-free conditions, and resource-allocation failures—that are characteristic of C-based image codecs and parsers handling untrusted image data. Defenders tracking this library should inventory downstream products that link it and treat image-processing pipelines as a vector for remote code execution; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cimg over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1010174CRITICAL CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image f | Jul 25, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-13568HIGH CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a malformed BMP image. | Jul 31, 2019 | 8.8 | 26 | NO | NO |
CVE-2020-25693HIGH A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed b | Dec 3, 2020 | 8.1 | 25 | NO | NO |
CVE-2018-7638HIGH An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th | Mar 2, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-7588HIGH An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image. | Mar 1, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-7641HIGH An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th | Mar 2, 2018 | 7.8 | 24 | NO | NO |
CVE-2018-7640HIGH An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th | Mar 2, 2018 | 7.8 | 24 | NO | NO |
CVE-2018-7639HIGH An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th | Mar 2, 2018 | 7.8 | 24 | NO | NO |
CVE-2018-7637HIGH An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. Th | Mar 2, 2018 | 7.8 | 24 | NO | NO |
CVE-2018-7589HIGH An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image. | Mar 1, 2018 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cimg.
Media articles that mention a CVE ID that affects a product developed by Cimg — matched by CVE ID, not by vendor name.