Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libbpg Project

First CVE: Jul 15, 2016Active for: 10 yearsTotal CVEs: 10
50.3
VTI Score
TOP TARGET

Libbpg is a narrowly scoped cryptographic library that, despite limited product breadth, occupies a prominent position in security-critical software infrastructure due to its embedding in downstream applications. The recurring vulnerability patterns center on memory-safety issues—buffer-bounds violations, integer overflows, NULL-pointer dereferences, and out-of-bounds reads and writes—that are characteristic of C-based cryptographic implementations and can propagate broadly across dependent systems. Defenders should track this vendor's advisories and prioritize remediation in products that integrate the library, as fixes typically require downstream rebuilding; current severity and exploitation metrics are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libbpg Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2016
10 years ago
Most Recent CVE
Aug 22, 2018
2,893 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-5637HIGH
The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which allows remote attackers to execute arbitrary code or cause a
Jul 15, 20168.829NONO
CVE-2018-12447HIGH
The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integer overflow that leads to a heap-based buffer overflow and r
Jun 15, 20188.826NONO
CVE-2017-14034HIGH
The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.7 and other products, miscalculates a memcpy destination address, which allows remote attacker
Nov 16, 20178.826NONO
CVE-2017-13136HIGH
The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.
Nov 16, 20178.826NONO
CVE-2017-14796HIGH
The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and application crash) or possibly have unspecifie
Sep 28, 20178.826NONO
CVE-2017-14795HIGH
The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecifi
Sep 28, 20178.826NONO
CVE-2017-14734HIGH
The build_msps function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspeci
Sep 25, 20178.826NONO
CVE-2017-13135HIGH
A NULL Pointer Dereference exists in VideoLAN x265, as used in libbpg 0.9.7 and other products, because the CUData::initialize function in common/cudata.cpp mishandles memory-alloc
Nov 16, 20177.824NONO
CVE-2016-8710HIGH
An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in Libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow v
Jan 26, 20177.821NONO
CVE-2017-2575MEDIUM
A vulnerability was found while fuzzing libbpg 0.9.7. It is a NULL pointer dereference issue due to missing check of the return value of function malloc in the BPG encoder. This vu
Aug 22, 20186.518NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
90%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (20.0%)
Network8 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required10 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libbpg Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libbpg Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libbpg Project's Products

View all 4 CNAs →

Top CWEs