Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libraw

First CVE: Aug 14, 2013Active for: 13 yearsTotal CVEs: 65
42.9
VTI Score
High

Libraw is a widely embedded image-processing library used across photography, imaging, and multimedia applications to decode raw camera formats, presenting a modest but notably prominent attack surface given its position in media-processing pipelines. The vendor's vulnerability footprint skews strongly toward critical-severity outcomes, reflecting the memory-safety demands of parsing untrusted binary image data from diverse camera sensors and manufacturers. Recurring exposure centers on out-of-bounds reads and writes, buffer-boundary violations, integer overflows, and NULL-pointer dereferences—weakness classes endemic to low-level format parsing and memory manipulation in native codebases handling variable-length, vendor-specific image structures. Defenders should treat this library's advisories as high-priority for any application chain that processes user-supplied raw images, particularly web services and batch-processing systems where input validation may be insufficient. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
65
Total CVEs
More Total CVEs than 99% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libraw over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2013
12 years ago
Most Recent CVE
Apr 7, 2026
108 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (65 CVEs).

65 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-24660CRITICAL
A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overf
Apr 7, 20269.838NONO
CVE-2026-24450CRITICAL
An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer ov
Apr 7, 20269.836NONO
CVE-2026-20884CRITICAL
An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow.
Apr 7, 20269.836NONO
CVE-2026-21413CRITICAL
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can le
Apr 7, 20269.835NONO
CVE-2026-20911CRITICAL
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead t
Apr 7, 20269.835NONO
CVE-2026-20889CRITICAL
A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overf
Apr 7, 20269.835NONO
CVE-2017-14265CRITICAL
A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution
Sep 11, 20179.832NONO
CVE-2017-6886CRITICAL
An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.
May 16, 20179.832NONO
CVE-2017-14608CRITICAL
In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly ex
Sep 20, 20179.130NONO
CVE-2018-5808HIGH
An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack-based buffer overflow and subsequently
Dec 7, 20188.829NONO
View all 65 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products65 CVEs
40%
34%
26%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (15.4%)
Network52 (80.0%)
Unknown3 (4.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (95.4%)
High0 (0.0%)
Unknown3 (4.6%)
User Interaction
None23 (35.4%)
Unknown3 (4.6%)
Required39 (60.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None62 (95.4%)
Unknown3 (4.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (65 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libraw.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libraw — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libraw's Products

View all 5 CNAs →

Top CWEs