Djvulibre is a document-viewing library for the DjVu format that, despite a narrow product scope, holds prominence in niche archival and scanning workflows where legacy document preservation remains important. The vulnerability exposure centers on memory-safety issues—out-of-bounds reads and writes, buffer-boundary violations, and divide-by-zero conditions—alongside code-injection vectors that are typical of image and document parsing libraries handling untrusted input. Defenders maintaining systems that process DjVu files should treat parser updates as a priority for supply-chain and data-ingestion pipelines; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Djvulibre Project over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6535HIGH DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memor | Dec 2, 2013 | 9.3 | 30 | NO | NO |
CVE-2019-18804HIGH DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp. | Nov 7, 2019 | 7.5 | 26 | NO | NO |
CVE-2021-3500HIGH A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other con | Jun 24, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-32493HIGH A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequen | Jun 24, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-32492HIGH A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequ | Jun 24, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-32491HIGH A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences | Jun 24, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-32490HIGH A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences. | Jun 24, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-3630MEDIUM An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This | Jun 30, 2021 | 5.5 | 21 | NO | NO |
CVE-2019-15145MEDIUM DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2 | Aug 18, 2019 | 5.5 | 21 | NO | NO |
CVE-2019-15144MEDIUM In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) b | Aug 18, 2019 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Djvulibre Project.
Media articles that mention a CVE ID that affects a product developed by Djvulibre Project — matched by CVE ID, not by vendor name.