Libbpg
Vendor:
First CVE: Jul 15, 2016 · Active for 10 years
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libbpg over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2016
10 years ago
Most Recent CVE
Aug 22, 2018
2,893 days ago
CVE Severity & Scoring
Libbpg10 CVEs
10%
90%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (20.0%)
Network8 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required10 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5637HIGH The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which allows remote attackers to execute arbitrary code or cause a | Jul 15, 2016 | 8.8 | 29 | NO | NO |
CVE-2018-12447HIGH The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integer overflow that leads to a heap-based buffer overflow and r | Jun 15, 2018 | 8.8 | 26 | NO | NO |
CVE-2017-14034HIGH The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.7 and other products, miscalculates a memcpy destination address, which allows remote attacker | Nov 16, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-13136HIGH The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference. | Nov 16, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-14796HIGH The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and application crash) or possibly have unspecifie | Sep 28, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-14795HIGH The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecifi | Sep 28, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-14734HIGH The build_msps function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspeci | Sep 25, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-13135HIGH A NULL Pointer Dereference exists in VideoLAN x265, as used in libbpg 0.9.7 and other products, because the CUData::initialize function in common/cudata.cpp mishandles memory-alloc | Nov 16, 2017 | 7.8 | 24 | NO | NO |
CVE-2016-8710HIGH An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in Libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow v | Jan 26, 2017 | 7.8 | 21 | NO | NO |
CVE-2017-2575MEDIUM A vulnerability was found while fuzzing libbpg 0.9.7. It is a NULL pointer dereference issue due to missing check of the return value of function malloc in the BPG encoder. This vu | Aug 22, 2018 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Libbpg
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.9.8 | 1 | 8.8 | 3.8% | 0 | 0 |
| 0.9.7 | 8 | 8.3 | 1.7% | 0 | 0 |
| 0.9.4 | 1 | 7.8 | 3.4% | 0 | 0 |