Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freeimage Project

First CVE: Sep 29, 2015Active for: 11 yearsTotal CVEs: 53
32.1
VTI Score
Medium

The FreeImage Project maintains a widely embedded image-processing library that, despite a narrow product footprint, sits deep in the software supply chain across graphics applications, scientific tools, and media software. Vulnerabilities concentrate in the core FreeImage library itself and recur through classic memory-safety weakness classes: buffer overflows (both stack and heap), out-of-bounds reads and writes, and integer-overflow conditions that arise from parsing and decoding untrusted image formats across dozens of supported codecs. These weakness classes are characteristic of C/C++ image parsers handling diverse, often malformed input, and they present a meaningful attack surface when the library is embedded in internet-facing or user-facing applications. Defenders should inventory downstream products that bundle FreeImage rather than tracking the library alone, since many deployments do not receive timely updates; live severity and exploitation status are shown alongside this summary.

FAUCET AI Generated
53
Total CVEs
More Total CVEs than 99% of tracked vendors
7.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Freeimage Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 29, 2015
10 years ago
Most Recent CVE
Jan 14, 2026
191 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (53 CVEs).

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-70968CRITICAL
FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
Jan 14, 20269.835NONO
CVE-2024-31570CRITICAL
libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.
Sep 19, 20249.827NONO
CVE-2019-12211HIGH
When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the
May 20, 20197.526NONO
CVE-2016-5684HIGH
An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory
Jan 6, 20177.826NONO
CVE-2019-12214HIGH
In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j2k.c. The value of l_N_ppm comes from the file read in, and
May 20, 20197.525NONO
CVE-2019-12212HIGH
When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack
May 20, 20197.525NONO
CVE-2024-28578HIGH
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in RAS format.
Mar 20, 20248.424NONO
CVE-2024-28580HIGH
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS for
Mar 20, 20248.423NONO
CVE-2023-47994HIGH
An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and
Jan 9, 20248.823NONO
CVE-2023-47992HIGH
An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or
Jan 9, 20248.823NONO
View all 53 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products53 CVEs
53%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local28 (52.8%)
Network24 (45.3%)
Unknown1 (1.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low52 (98.1%)
High0 (0.0%)
Unknown1 (1.9%)
User Interaction
None29 (54.7%)
Unknown1 (1.9%)
Required23 (43.4%)
Privileges Required
Low8 (15.1%)
High0 (0.0%)
None44 (83.0%)
Unknown1 (1.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (53 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freeimage Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freeimage Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freeimage Project's Products

View all 4 CNAs →

Top CWEs