Flif is a specialized image-format codec with a narrow product footprint centered on its free lossless image-format implementation. The recurring vulnerability pattern reflects the parsing and resource-management demands of image decoders: exposures cluster around out-of-bounds memory access, unbounded resource allocation, and excessive iteration during image decoding, which are structural hazards in format parsers handling untrusted input. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flif over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14373HIGH An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a heap-based buffer over-read in libpng via a craft | Jul 28, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-12109HIGH An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC<FileIO>::process function in transform/palette_C.hpp allows remote attackers to cause a deni | Jun 11, 2018 | 7.8 | 23 | NO | NO |
CVE-2018-10972HIGH An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC::process function in transform/palette_C.hpp allows remote attackers to cause a denial of se | May 10, 2018 | 7.8 | 23 | NO | NO |
CVE-2018-11507MEDIUM An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long loop in image_load_pnm in image/image-pnm.cpp. | May 28, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-14876MEDIUM An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a longjmp that leads to an uninitialized stack fram | Aug 3, 2018 | 5.5 | 20 | NO | NO |
CVE-2017-14232MEDIUM The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) vi | Aug 15, 2019 | 5.5 | 19 | NO | NO |
CVE-2018-10971MEDIUM An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote attackers to cause a denial of service (attempted excessive me | May 10, 2018 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flif.
Media articles that mention a CVE ID that affects a product developed by Flif — matched by CVE ID, not by vendor name.