The Python Imaging Project maintains Pillow, a widely used image-processing library embedded across Python applications and web services that ingest or manipulate image files from untrusted sources. The vulnerability signal centers on memory-safety issues in image parsing and codec handling, particularly improper buffer-boundary enforcement when processing image data.
The number and severity of CVEs published that impact products developed by Python Imaging Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2533MEDIUM Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial | Apr 13, 2016 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Python Imaging Project.
Media articles that mention a CVE ID that affects a product developed by Python Imaging Project — matched by CVE ID, not by vendor name.