Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Djvulibre Project

First CVE: Dec 2, 2013Active for: 13 yearsTotal CVEs: 14
34.9
VTI Score
Medium

Djvulibre is a document-viewing library for the DjVu format that, despite a narrow product scope, holds prominence in niche archival and scanning workflows where legacy document preservation remains important. The vulnerability exposure centers on memory-safety issues—out-of-bounds reads and writes, buffer-boundary violations, and divide-by-zero conditions—alongside code-injection vectors that are typical of image and document parsing libraries handling untrusted input. Defenders maintaining systems that process DjVu files should treat parser updates as a priority for supply-chain and data-ingestion pipelines; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Djvulibre Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 2013
12 years ago
Most Recent CVE
Aug 22, 2023
1,070 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-6535HIGH
DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memor
Dec 2, 20139.330NONO
CVE-2019-18804HIGH
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
Nov 7, 20197.526NONO
CVE-2021-3500HIGH
A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other con
Jun 24, 20217.825NONO
CVE-2021-32493HIGH
A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequen
Jun 24, 20217.825NONO
CVE-2021-32492HIGH
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequ
Jun 24, 20217.825NONO
CVE-2021-32491HIGH
A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences
Jun 24, 20217.825NONO
CVE-2021-32490HIGH
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences.
Jun 24, 20217.825NONO
CVE-2021-3630MEDIUM
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This
Jun 30, 20215.521NONO
CVE-2019-15145MEDIUM
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2
Aug 18, 20195.521NONO
CVE-2019-15144MEDIUM
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) b
Aug 18, 20195.521NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
50%
50%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local10 (71.4%)
Network3 (21.4%)
Unknown1 (7.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High0 (0.0%)
Unknown1 (7.1%)
User Interaction
None1 (7.1%)
Unknown1 (7.1%)
Required12 (85.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None13 (92.9%)
Unknown1 (7.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Djvulibre Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Djvulibre Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Djvulibre Project's Products

View all 3 CNAs →

Top CWEs