Imlib2
Vendor:
First CVE: Sep 16, 2004 · Active for 21 years
22
Total CVEs
More Total CVEs than 94% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Imlib2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2004
21 years ago
Most Recent CVE
Feb 9, 2024
896 days ago
CVE Severity & Scoring
Imlib222 CVEs
9%
18%
64%
9%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (54.5%)
Unknown10 (45.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (54.5%)
High0 (0.0%)
Unknown10 (45.5%)
User Interaction
None9 (40.9%)
Unknown10 (45.5%)
Required3 (13.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (54.5%)
Unknown10 (45.5%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4024CRITICAL Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap | May 13, 2016 | 9.8 | 33 | NO | NO |
CVE-2016-3994HIGH The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers a | May 13, 2016 | 8.2 | 27 | NO | NO |
CVE-2016-3993HIGH Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (out-of-bounds read and applicatio | May 13, 2016 | 7.5 | 25 | NO | NO |
CVE-2011-5326HIGH imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse. | May 13, 2016 | 7.5 | 25 | NO | NO |
CVE-2008-6079HIGH imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related | Feb 6, 2009 | 10.0 | 25 | NO | NO |
CVE-2024-25450HIGH imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts(). | Feb 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-25448HIGH An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image. | Feb 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-25447HIGH An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image. | Feb 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2020-12761CRITICAL modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color m | May 9, 2020 | 9.1 | 23 | NO | NO |
CVE-2004-0827HIGH Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and | Sep 16, 2004 | 7.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Imlib2
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.1 | 3 | 8.8 | 0.7% | 0 | 0 |
| 1.6.0 | 1 | 9.1 | 1.6% | 0 | 0 |
| 1.4.3 | 1 | 6.8 | 2.0% | 0 | 0 |
| 1.4.2 | 1 | 7.5 | 3.6% | 0 | 0 |
| 1.4.0 | 1 | 10.0 | 2.8% | 0 | 0 |
| 1.3.0 | 1 | 10.0 | 2.8% | 0 | 0 |
| 1.3 | 1 | 5.1 | 4.2% | 0 | 0 |
| 1.2.2 | 2 | 7.5 | 3.5% | 0 | 0 |
| 1.2.1 | 2 | 7.5 | 3.5% | 0 | 0 |
| 1.1.2 | 5 | 5.1 | 3.5% | 0 | 0 |
| 1.1.1 | 8 | 5.7 | 3.9% | 0 | 0 |
| 1.1 | 8 | 5.7 | 3.9% | 0 | 0 |
| 1.0.5 | 8 | 5.7 | 3.9% | 0 | 0 |
| 1.0.4 | 8 | 5.7 | 3.9% | 0 | 0 |
| 1.0.3 | 8 | 5.7 | 3.9% | 0 | 0 |
| 1.0.2 | 8 | 5.7 | 3.9% | 0 | 0 |
| 1.0.1 | 8 | 5.7 | 3.9% | 0 | 0 |
| 1.0 | 8 | 5.7 | 3.9% | 0 | 0 |