The Hugin Project maintains a panoramic image stitching application that, despite a narrow product scope, represents a specialized tool for computational photography with exposure across photography and geospatial workflows. Vulnerabilities affecting the Hugin image-processing pipeline center on memory-safety issues such as out-of-bounds writes, use-after-free conditions, and assertion reachability that typically arise in C++ image codec and buffer-handling logic. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hugin Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25446HIGH An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image. | Feb 9, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-25445HIGH Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure. | Feb 9, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-25443HIGH An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image. | Feb 9, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-25442HIGH An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image. | Feb 9, 2024 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hugin Project.
Media articles that mention a CVE ID that affects a product developed by Hugin Project — matched by CVE ID, not by vendor name.