The Fltk Project maintains a lightweight, cross-platform graphical user interface toolkit that, despite a narrow product scope, serves as a dependency in specialized embedded and desktop applications where memory safety and pointer handling are critical. Its disclosed vulnerabilities center on memory-access issues such as NULL pointer dereferences and out-of-bounds reads, reflecting the low-level nature of graphics rendering code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fltk Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28308CRITICAL An issue was discovered in the fltk crate before 0.15.3 for Rust. There is an out-of bounds read because the pixmap constructor lacks pixmap input validation. | Mar 12, 2021 | 9.1 | 27 | NO | NO |
CVE-2021-28307HIGH An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a non-raster image for a window icon. | Mar 12, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-28306HIGH An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a multi label type if the image is nonexistent. | Mar 12, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fltk Project.
Media articles that mention a CVE ID that affects a product developed by Fltk Project — matched by CVE ID, not by vendor name.