Libbpg is a narrowly scoped cryptographic library that, despite limited product breadth, occupies a prominent position in security-critical software infrastructure due to its embedding in downstream applications. The recurring vulnerability patterns center on memory-safety issues—buffer-bounds violations, integer overflows, NULL-pointer dereferences, and out-of-bounds reads and writes—that are characteristic of C-based cryptographic implementations and can propagate broadly across dependent systems. Defenders should track this vendor's advisories and prioritize remediation in products that integrate the library, as fixes typically require downstream rebuilding; current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libbpg Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5637HIGH The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which allows remote attackers to execute arbitrary code or cause a | Jul 15, 2016 | 8.8 | 29 | NO | NO |
CVE-2018-12447HIGH The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integer overflow that leads to a heap-based buffer overflow and r | Jun 15, 2018 | 8.8 | 26 | NO | NO |
CVE-2017-14034HIGH The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.7 and other products, miscalculates a memcpy destination address, which allows remote attacker | Nov 16, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-13136HIGH The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference. | Nov 16, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-14796HIGH The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and application crash) or possibly have unspecifie | Sep 28, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-14795HIGH The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecifi | Sep 28, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-14734HIGH The build_msps function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspeci | Sep 25, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-13135HIGH A NULL Pointer Dereference exists in VideoLAN x265, as used in libbpg 0.9.7 and other products, because the CUData::initialize function in common/cudata.cpp mishandles memory-alloc | Nov 16, 2017 | 7.8 | 24 | NO | NO |
CVE-2016-8710HIGH An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in Libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow v | Jan 26, 2017 | 7.8 | 21 | NO | NO |
CVE-2017-2575MEDIUM A vulnerability was found while fuzzing libbpg 0.9.7. It is a NULL pointer dereference issue due to missing check of the return value of function malloc in the BPG encoder. This vu | Aug 22, 2018 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libbpg Project.
Media articles that mention a CVE ID that affects a product developed by Libbpg Project — matched by CVE ID, not by vendor name.