Ngiflib
Vendor:
First CVE: May 2, 2018 · Active for 8 years
17
Total CVEs
More Total CVEs than 93% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ngiflib over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2018
8 years ago
Most Recent CVE
Aug 11, 2023
1,078 days ago
CVE Severity & Scoring
Ngiflib17 CVEs
35%
53%
12%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (23.5%)
Network13 (76.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (23.5%)
Unknown0 (0.0%)
Required13 (76.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None17 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11576CRITICAL ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor. | May 31, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-11575CRITICAL ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg. | May 31, 2018 | 9.8 | 28 | NO | NO |
CVE-2021-36530HIGH ngiflib 0.4 has a heap overflow in GetByteStr() at ngiflib.c:108 in NGIFLIB_NO_FILE mode, GetByteStr() copy memory buffer without checking the boundary. | Aug 27, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-20219HIGH ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c. | Jan 2, 2020 | 8.8 | 27 | NO | NO |
CVE-2018-10717HIGH The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service | May 3, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-36531HIGH ngiflib 0.4 has a heap overflow in GetByte() at ngiflib.c:70 in NGIFLIB_NO_FILE mode, GetByte() reads memory buffer without checking the boundary. | Aug 27, 2021 | 8.8 | 26 | NO | NO |
CVE-2019-16347HIGH ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled. | Sep 16, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-16346HIGH ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled. | Sep 16, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-19011HIGH MiniUPnP ngiflib 0.4 has a NULL pointer dereference in GifIndexToTrueColor in ngiflib.c via a file that lacks a palette. | Nov 17, 2019 | 7.5 | 24 | NO | NO |
CVE-2018-10677HIGH The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixel | May 2, 2018 | 8.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Ngiflib
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.4 | 14 | 8.2 | 1.3% | 0 | 0 |