Pixman is a small, foundational image-processing library embedded across many desktop and server applications, particularly in graphics stacks and rendering pipelines, where its role in memory-intensive pixel operations creates substantial downstream exposure. Vulnerabilities affecting the library skew strongly toward critical-severity outcomes and recur through integer-arithmetic weakness classes—overflow, underflow, and divide-by-zero conditions—that are endemic to bitmap manipulation at scale and can propagate through any application that links the library. Defenders should prioritize patching this vendor's releases despite its modest CVE volume, since a single flaw can affect rendering engines, web browsers, and graphical servers across their entire installed bases; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pixman over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9766CRITICAL Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly exe | Apr 13, 2016 | 9.8 | 32 | NO | NO |
CVE-2015-5297CRITICAL An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application | Jul 31, 2019 | 9.8 | 24 | NO | NO |
CVE-2022-44638HIGH In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y. | Nov 3, 2022 | 8.8 | 22 | NO | NO |
CVE-2023-37769MEDIUM stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c. | Jul 17, 2023 | 6.5 | 19 | NO | NO |
CVE-2013-6425MEDIUM Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial o | Jan 18, 2014 | 5.0 | 16 | NO | NO |
CVE-2013-6424MEDIUM Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value. | Jan 18, 2014 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pixman.
Media articles that mention a CVE ID that affects a product developed by Pixman — matched by CVE ID, not by vendor name.