Dcraw is a lightweight, widely used command-line tool for processing raw digital camera image files, positioned as a niche but structurally important utility in photography and image-processing workflows. Its vulnerability surface concentrates in the parser and buffer-handling routines that decode proprietary camera formats, with recurrent weakness classes including buffer-boundary violations, out-of-bounds reads and writes, integer overflows, and improper input validation—all characteristic of binary format parsing under tight constraints. Defenders should treat this utility as a supply-chain component for workflows that ingest untrusted raw image files; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dcraw Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19655HIGH A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flo | Nov 29, 2018 | 8.8 | 28 | NO | NO |
CVE-2021-3624HIGH There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system. | Apr 18, 2022 | 7.8 | 25 | NO | NO |
CVE-2018-19566HIGH A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or lea | Nov 26, 2018 | 7.1 | 23 | NO | NO |
CVE-2018-19565HIGH A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak | Nov 26, 2018 | 7.1 | 23 | NO | NO |
CVE-2018-19568MEDIUM A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw cod | Nov 26, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-19567MEDIUM A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code. | Nov 26, 2018 | 5.5 | 20 | NO | NO |
CVE-2015-3885MEDIUM Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer ove | May 19, 2015 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dcraw Project.
Media articles that mention a CVE ID that affects a product developed by Dcraw Project — matched by CVE ID, not by vendor name.