Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Saitoha

First CVE: Jul 15, 2018Active for: 8 yearsTotal CVEs: 48
38.2
VTI Score
Medium

Saitoha maintains libsixel, a specialized image-encoding library that converts images to the SIXEL graphics format, a niche but durably deployed component in terminal emulation and legacy graphics environments. The vendor's vulnerability footprint, while modestly represented in absolute terms, punches above its size because the library sits in the parsing path of potentially untrusted image data across embedded systems and terminal applications. Recurring vulnerabilities center on memory-safety issues—out-of-bounds reads and writes, heap-based buffer overflows, integer overflows, and use-after-free conditions—that are characteristic of C-based image parsers handling variable-length, format-complex input. These weaknesses tend toward serious outcomes, reflecting the difficulty of safely parsing image streams without bounds-checking and type-safety guarantees. Defenders should include libsixel in supply-chain reviews of terminal emulators and graphics applications, particularly in headless or automation contexts where data origin is less controlled; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
48
Total CVEs
More Total CVEs than 98% of tracked vendors
6.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Saitoha over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2018
8 years ago
Most Recent CVE
May 14, 2026
71 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-9300HIGH
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. T
Aug 21, 20257.831NONO
CVE-2019-19636CRITICAL
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.
Dec 8, 20199.831NONO
CVE-2019-19638CRITICAL
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an integer overflow.
Dec 8, 20199.830NONO
CVE-2019-19635CRITICAL
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.
Dec 8, 20199.830NONO
CVE-2026-44636HIGH
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation ca
May 14, 20267.828NONO
CVE-2022-27046HIGH
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
Apr 8, 20228.828NONO
CVE-2022-27044HIGH
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
Apr 8, 20228.828NONO
CVE-2026-33023HIGH
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerab
Apr 14, 20267.827NONO
CVE-2020-21548HIGH
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
Sep 17, 20218.827NONO
CVE-2020-21547HIGH
Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
Sep 17, 20218.827NONO
View all 48 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products48 CVEs
44%
46%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local19 (39.6%)
Network29 (60.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (95.8%)
High2 (4.2%)
Unknown0 (0.0%)
User Interaction
None11 (22.9%)
Unknown0 (0.0%)
Required37 (77.1%)
Privileges Required
Low2 (4.2%)
High0 (0.0%)
None46 (95.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Saitoha.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Saitoha — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Saitoha's Products

View all 3 CNAs →

Top CWEs