Giflib

Vendor:

First CVE: Apr 13, 2016 · Active for 10 years

14
Total CVEs
More Total CVEs than 92% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Giflib over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 13, 2016
10 years ago
Most Recent CVE
Mar 18, 2026
132 days ago

CVE Severity & Scoring

Giflib14 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local7 (50.0%)
Network7 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None5 (35.7%)
Unknown0 (0.0%)
Required9 (64.3%)
Privileges Required
Low2 (14.3%)
High0 (0.0%)
None12 (85.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.
Jan 23, 20179.830NONO
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension b
Mar 18, 20268.229NONO
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerabil
Mar 10, 20267.027NONO
A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file.
Jun 14, 20228.827NONO
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Pr
May 26, 20188.827NONO
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain Crn
May 26, 20188.827NONO
An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.
Apr 21, 20217.124NONO
Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.
Sep 30, 20246.522NONO
Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c
Nov 22, 20237.122NONO
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data stru
Aug 17, 20196.522NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Giflib

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.2.227.30.5%00
5.2.136.00.7%00
5.1.418.81.5%00
5.1.219.81.6%00