Freeimage

Vendor:

First CVE: Sep 29, 2015 · Active for 10 years

53
Total CVEs
More Total CVEs than 98% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Freeimage over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 29, 2015
10 years ago
Most Recent CVE
Jan 14, 2026
195 days ago

CVE Severity & Scoring

Freeimage53 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local28 (52.8%)
Network24 (45.3%)
Unknown1 (1.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low52 (98.1%)
High0 (0.0%)
Unknown1 (1.9%)
User Interaction
None29 (54.7%)
Unknown1 (1.9%)
Required23 (43.4%)
Privileges Required
Low8 (15.1%)
High0 (0.0%)
None44 (83.0%)
Unknown1 (1.9%)

Top CVEs

Signals from CVEs in this product scope (53 CVEs).

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
Jan 14, 20269.835NONO
libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.
Sep 19, 20249.827NONO
When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the
May 20, 20197.526NONO
An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory
Jan 6, 20177.826NONO
In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j2k.c. The value of l_N_ppm comes from the file read in, and
May 20, 20197.525NONO
When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack
May 20, 20197.525NONO
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in RAS format.
Mar 20, 20248.424NONO
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS for
Mar 20, 20248.423NONO
An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and
Jan 9, 20248.823NONO
An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or
Jan 9, 20248.823NONO

Exploit Exposure

Signals from CVEs in this product scope (53 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (53 CVEs).

Media Mentions

Signals from CVEs in this product scope (53 CVEs).

Top CNAs Publishing CVEs For Freeimage

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.19.0286.80.5%00
3.18.0157.41.1%00
3.17.017.81.8%00
1.18.018.81.0%00