Libcaca is a specialized graphics library for rendering text-based visual content, and despite modest disclosure volume, occupies a niche but significant position in terminal and embedded display applications across Unix-like systems. Its vulnerability footprint centers on a single product and recurs through memory-safety and arithmetic weakness classes—buffer overflows, integer overflows, divide-by-zero conditions, and out-of-bounds writes—that are characteristic of C libraries performing pixel-to-character conversion and low-level rendering. Defenders should monitor this library's releases when it is embedded in terminal multiplexers, accessibility tools, or media players, as memory corruption in graphics processing can affect system stability; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libcaca Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20549HIGH There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19. | Dec 28, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-20548HIGH There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data. | Dec 28, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-20545HIGH There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data. | Dec 28, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-20546HIGH There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case. | Dec 28, 2018 | 8.1 | 27 | NO | NO |
CVE-2021-30499HIGH A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences. | May 27, 2021 | 7.8 | 26 | NO | NO |
CVE-2018-20547HIGH There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data. | Dec 28, 2018 | 8.1 | 26 | NO | NO |
CVE-2021-30498HIGH A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences. | May 26, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-3410HIGH A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context | Feb 23, 2021 | 7.8 | 25 | NO | NO |
CVE-2022-0856MEDIUM libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service | Mar 10, 2022 | 6.5 | 23 | NO | NO |
CVE-2018-20544MEDIUM There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19. | Dec 28, 2018 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libcaca Project.
Media articles that mention a CVE ID that affects a product developed by Libcaca Project — matched by CVE ID, not by vendor name.