Entropymine develops a small collection of file-conversion and forensic image-analysis tools, particularly ImageWorsener and Deark, that process untrusted binary formats and operate on low-level data structures common to image and archive parsing. Vulnerabilities affecting the vendor center on memory-safety and resource-handling weaknesses such as out-of-bounds reads, NULL-pointer dereferences, divide-by-zero conditions, and uncontrolled resource consumption—defects characteristic of parsers operating on hostile or malformed input without strict bounds enforcement. The focused product line and narrow attack surface mean remediation is straightforward for affected users, though the tools' use in forensic and data-recovery workflows means their availability is important to specialists. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Entropymine over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8326HIGH libimageworsener.a in ImageWorsener before 1.3.1 has "left shift cannot be represented in type int" undefined behavior issues, which might allow remote attackers to cause a denial | Apr 29, 2017 | 8.8 | 29 | NO | NO |
CVE-2018-16782HIGH libimageworsener.a in ImageWorsener 1.3.2 has a buffer overflow in the bmpr_read_rle_internal function in imagew-bmp.c. | Sep 10, 2018 | 8.8 | 28 | NO | NO |
CVE-2017-8325HIGH The iw_process_cols_to_intermediate function in imagew-main.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (heap-based b | Apr 29, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-9094MEDIUM The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image. | May 19, 2017 | 6.5 | 23 | NO | NO |
CVE-2017-9093MEDIUM The my_skip_input_data_fn function in imagew-jpeg.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted | May 19, 2017 | 6.5 | 23 | NO | NO |
CVE-2017-8327MEDIUM The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (memory consumption) vi | Apr 29, 2017 | 6.5 | 23 | NO | NO |
CVE-2017-9207MEDIUM The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) v | May 23, 2017 | 6.5 | 22 | NO | NO |
CVE-2017-9206MEDIUM The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) v | May 23, 2017 | 6.5 | 22 | NO | NO |
CVE-2017-9205MEDIUM The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a c | May 23, 2017 | 6.5 | 22 | NO | NO |
CVE-2017-9204MEDIUM The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a c | May 23, 2017 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Entropymine.
Media articles that mention a CVE ID that affects a product developed by Entropymine — matched by CVE ID, not by vendor name.