Libsixel is a focused library for encoding and decoding SIXEL graphics format, deployed across terminal emulators and image-processing tools despite its narrow product scope. Its vulnerability profile centers on memory-safety issues—including NULL-pointer dereferences, out-of-bounds writes, reachable assertions, and use-after-free conditions—typical of C-based parsing libraries that handle untrusted image data; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libsixel over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41715HIGH libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379. | Apr 8, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-40656HIGH libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867. | Apr 8, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-45340MEDIUM In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PI | Jan 25, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-27938MEDIUM stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw. | Mar 26, 2022 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libsixel.
Media articles that mention a CVE ID that affects a product developed by Libsixel — matched by CVE ID, not by vendor name.