Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libcaca Project

First CVE: Dec 28, 2018Active for: 8 yearsTotal CVEs: 10
49.2
VTI Score
High

Libcaca is a specialized graphics library for rendering text-based visual content, and despite modest disclosure volume, occupies a niche but significant position in terminal and embedded display applications across Unix-like systems. Its vulnerability footprint centers on a single product and recurs through memory-safety and arithmetic weakness classes—buffer overflows, integer overflows, divide-by-zero conditions, and out-of-bounds writes—that are characteristic of C libraries performing pixel-to-character conversion and low-level rendering. Defenders should monitor this library's releases when it is embedded in terminal multiplexers, accessibility tools, or media players, as memory corruption in graphics processing can affect system stability; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libcaca Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2018
7 years ago
Most Recent CVE
Mar 10, 2022
1,597 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-20549HIGH
There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.
Dec 28, 20188.828NONO
CVE-2018-20548HIGH
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data.
Dec 28, 20188.828NONO
CVE-2018-20545HIGH
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
Dec 28, 20188.828NONO
CVE-2018-20546HIGH
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
Dec 28, 20188.127NONO
CVE-2021-30499HIGH
A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.
May 27, 20217.826NONO
CVE-2018-20547HIGH
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.
Dec 28, 20188.126NONO
CVE-2021-30498HIGH
A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.
May 26, 20217.825NONO
CVE-2021-3410HIGH
A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context
Feb 23, 20217.825NONO
CVE-2022-0856MEDIUM
libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service
Mar 10, 20226.523NONO
CVE-2018-20544MEDIUM
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
Dec 28, 20186.522NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
20%
80%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (30.0%)
Network7 (70.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (10.0%)
Unknown0 (0.0%)
Required9 (90.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libcaca Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libcaca Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libcaca Project's Products

View all 3 CNAs →

Top CWEs