Imlib2

Vendor:

First CVE: Sep 16, 2004 · Active for 21 years

22
Total CVEs
More Total CVEs than 94% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Imlib2 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2004
21 years ago
Most Recent CVE
Feb 9, 2024
896 days ago

CVE Severity & Scoring

Imlib222 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (54.5%)
Unknown10 (45.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (54.5%)
High0 (0.0%)
Unknown10 (45.5%)
User Interaction
None9 (40.9%)
Unknown10 (45.5%)
Required3 (13.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (54.5%)
Unknown10 (45.5%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap
May 13, 20169.833NONO
The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers a
May 13, 20168.227NONO
Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (out-of-bounds read and applicatio
May 13, 20167.525NONO
imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.
May 13, 20167.525NONO
imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related
Feb 6, 200910.025NONO
imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().
Feb 9, 20248.824NONO
An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
Feb 9, 20248.824NONO
An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
Feb 9, 20248.824NONO
modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color m
May 9, 20209.123NONO
Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and
Sep 16, 20047.523NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Imlib2

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.138.80.7%00
1.6.019.11.6%00
1.4.316.82.0%00
1.4.217.53.6%00
1.4.0110.02.8%00
1.3.0110.02.8%00
1.315.14.2%00
1.2.227.53.5%00
1.2.127.53.5%00
1.1.255.13.5%00
1.1.185.73.9%00
1.185.73.9%00
1.0.585.73.9%00
1.0.485.73.9%00
1.0.385.73.9%00
1.0.285.73.9%00
1.0.185.73.9%00
1.085.73.9%00