Creolabs' vulnerability profile concentrates in Gravity, a modestly represented but more prominent-than-typical media framework, where disclosures skew strongly toward critical-severity outcomes across memory-safety and input-handling weaknesses. The recurring classes—buffer overflows, NULL-pointer dereferences, double-free conditions, and out-of-bounds reads—reflect the memory-manipulation risks characteristic of native multimedia processing code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Creolabs over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000437CRITICAL Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution. | Jan 2, 2018 | 9.8 | 32 | NO | NO |
CVE-2017-1000073CRITICAL Creolabs Gravity version 1.0 is vulnerable to a heap overflow in an undisclosed component that can result in arbitrary code execution. | Jul 17, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-1000075CRITICAL Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function | Jul 17, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-1000074CRITICAL Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the string_repeat() function. | Jul 17, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-1000072CRITICAL Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locations | Jul 17, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-1000172CRITICAL Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sublexer' pointer has been freed. Line 542 of gravity_lexer.c. | Nov 17, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-1000173CRITICAL Creolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a buffer, we can break out of the bounds checking of that buf | Nov 17, 2017 | 9.8 | 28 | NO | NO |
CVE-2021-32284HIGH An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_register_pop_context_protect() located in gravity_ircode.c. It allows an | Sep 20, 2021 | 7.8 | 23 | NO | NO |
CVE-2021-32281HIGH An issue was discovered in gravity through 0.8.1. A heap-buffer-overflow exists in the function gnode_function_add_upvalue located in gravity_ast.c. It allows an attacker to cause | Sep 20, 2021 | 7.8 | 23 | NO | NO |
CVE-2018-13795HIGH Gravity before 0.5.1 does not support a maximum recursion depth. | Jul 9, 2018 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Creolabs.
Media articles that mention a CVE ID that affects a product developed by Creolabs — matched by CVE ID, not by vendor name.