Monostream's vulnerability footprint centers on a specialized image and media processing product, TIFIG, which handles low-level binary parsing and resource management tasks. The recurring weakness classes—including NULL-pointer dereferences, resource-exhaustion conditions, memory leaks, out-of-bounds writes, and use-after-free errors—reflect the memory-safety challenges inherent to native-code image handling and the parsing complexity of handling untrusted media formats. Current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Monostream over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36152MEDIUM tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp. | Aug 16, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-36153MEDIUM tifig v0.2.2 was discovered to contain a segmentation violation via std::vector<unsigned int, std::allocator<unsigned int> >::size() const at /bits/stl_vector.h. | Aug 16, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-36151MEDIUM tifig v0.2.2 was discovered to contain a segmentation violation via getType() at /common/bbox.cpp. | Aug 16, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-36150MEDIUM tifig v0.2.2 was discovered to contain a heap-buffer overflow via __asan_memmove at /asan/asan_interceptors_memintrinsics.cpp. | Aug 16, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-36149MEDIUM tifig v0.2.2 was discovered to contain a heap-use-after-free via temInfoEntry(). | Aug 16, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-36155MEDIUM tifig v0.2.2 was discovered to contain a resource allocation issue via operator new(unsigned long) at asan_new_delete.cpp. | Aug 16, 2022 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Monostream.
Media articles that mention a CVE ID that affects a product developed by Monostream — matched by CVE ID, not by vendor name.