Image Processing Project maintains a narrowly scoped image-processing library whose vulnerability profile centers on input-handling and data-protection issues, particularly improper validation of image data and premature exposure of sensitive information. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Image Processing Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24720CRITICAL image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a seri | Mar 1, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-21573MEDIUM An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file. | Nov 2, 2021 | 5.5 | 20 | NO | NO |
CVE-2005-0406MEDIUM A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive | Feb 14, 2005 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Image Processing Project.
Media articles that mention a CVE ID that affects a product developed by Image Processing Project — matched by CVE ID, not by vendor name.