Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Entropymine

First CVE: Apr 6, 2017Active for: 9 yearsTotal CVEs: 26
21.9
VTI Score
Low

Entropymine develops a small collection of file-conversion and forensic image-analysis tools, particularly ImageWorsener and Deark, that process untrusted binary formats and operate on low-level data structures common to image and archive parsing. Vulnerabilities affecting the vendor center on memory-safety and resource-handling weaknesses such as out-of-bounds reads, NULL-pointer dereferences, divide-by-zero conditions, and uncontrolled resource consumption—defects characteristic of parsers operating on hostile or malformed input without strict bounds enforcement. The focused product line and narrow attack surface mean remediation is straightforward for affected users, though the tools' use in forensic and data-recovery workflows means their availability is important to specialists. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Entropymine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2017
9 years ago
Most Recent CVE
Dec 19, 2022
1,313 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-8326HIGH
libimageworsener.a in ImageWorsener before 1.3.1 has "left shift cannot be represented in type int" undefined behavior issues, which might allow remote attackers to cause a denial
Apr 29, 20178.829NONO
CVE-2018-16782HIGH
libimageworsener.a in ImageWorsener 1.3.2 has a buffer overflow in the bmpr_read_rle_internal function in imagew-bmp.c.
Sep 10, 20188.828NONO
CVE-2017-8325HIGH
The iw_process_cols_to_intermediate function in imagew-main.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (heap-based b
Apr 29, 20178.828NONO
CVE-2017-9094MEDIUM
The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.
May 19, 20176.523NONO
CVE-2017-9093MEDIUM
The my_skip_input_data_fn function in imagew-jpeg.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted
May 19, 20176.523NONO
CVE-2017-8327MEDIUM
The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (memory consumption) vi
Apr 29, 20176.523NONO
CVE-2017-9207MEDIUM
The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) v
May 23, 20176.522NONO
CVE-2017-9206MEDIUM
The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) v
May 23, 20176.522NONO
CVE-2017-9205MEDIUM
The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a c
May 23, 20176.522NONO
CVE-2017-9204MEDIUM
The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a c
May 23, 20176.522NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
85%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local11 (42.3%)
Network15 (57.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (96.2%)
High1 (3.8%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required26 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None26 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Entropymine.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Entropymine — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Entropymine's Products

View all 1 CNAs →

Top CWEs