Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pixman

First CVE: Jan 18, 2014Active for: 13 yearsTotal CVEs: 6

Pixman is a small, foundational image-processing library embedded across many desktop and server applications, particularly in graphics stacks and rendering pipelines, where its role in memory-intensive pixel operations creates substantial downstream exposure. Vulnerabilities affecting the library skew strongly toward critical-severity outcomes and recur through integer-arithmetic weakness classes—overflow, underflow, and divide-by-zero conditions—that are endemic to bitmap manipulation at scale and can propagate through any application that links the library. Defenders should prioritize patching this vendor's releases despite its modest CVE volume, since a single flaw can affect rendering engines, web browsers, and graphical servers across their entire installed bases; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pixman over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2014
12 years ago
Most Recent CVE
Jul 17, 2023
1,103 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-9766CRITICAL
Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly exe
Apr 13, 20169.832NONO
CVE-2015-5297CRITICAL
An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application
Jul 31, 20199.824NONO
CVE-2022-44638HIGH
In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.
Nov 3, 20228.822NONO
CVE-2023-37769MEDIUM
stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.
Jul 17, 20236.519NONO
CVE-2013-6425MEDIUM
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial o
Jan 18, 20145.016NONO
CVE-2013-6424MEDIUM
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
Jan 18, 20145.016NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
17%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (66.7%)
Unknown2 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (66.7%)
High0 (0.0%)
Unknown2 (33.3%)
User Interaction
None2 (33.3%)
Unknown2 (33.3%)
Required2 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (66.7%)
Unknown2 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pixman.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pixman — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pixman's Products

View all 2 CNAs →

Top CWEs