lcdf records
6 published records for vendor lcdf.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-415 Double Free1
- CWE-416 Use After Free1
- CWE-476 NULL Pointer Dereference1
- CWE-697 Incorrect Comparison1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-1000421No exploit | Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code executionlcdf · gifsicle · CWE-416 | Critical9.8 | — | 2.7% | Jan 2, 2018 |
32Monitor | CVE-2017-18120No exploit | A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unslcdf · gifsicle · CWE-415 | High7.8 | — | 1.8% | Feb 2, 2018 |
31Monitor | CVE-2023-46009No exploit | gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.lcdf · gifsicle · CWE-697 | High7.8 | — | 0.3% | Oct 18, 2023 |
31Monitor | CVE-2023-36193No exploit | Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c.lcdf · gifsicle · CWE-787 | High7.8 | — | 0.3% | Jun 22, 2023 |
30Monitor | CVE-2020-19752No exploit | The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.lcdf · gifsicle · CWE-476 | High7.5 | — | 1.6% | Sep 7, 2021 |
22Monitor | CVE-2023-44821No exploit | Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memorylcdf · gifsicle · CWE-401 | Medium5.5 | — | 0.3% | Oct 9, 2023 |
- CVE-2017-100042140Plan
Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution
CriticalCVSS 9.8No exploitEPSS 3%lcdf · gifsicleJan 2, 2018
- CVE-2017-1812032Monitor
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or uns
HighCVSS 7.8No exploitEPSS 2%lcdf · gifsicleFeb 2, 2018
- CVE-2023-4600931Monitor
gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.
HighCVSS 7.8No exploitEPSS 0%lcdf · gifsicleOct 18, 2023
- CVE-2023-3619331Monitor
Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c.
HighCVSS 7.8No exploitEPSS 0%lcdf · gifsicleJun 22, 2023
- CVE-2020-1975230Monitor
The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
HighCVSS 7.5No exploitEPSS 2%lcdf · gifsicleSep 7, 2021
- CVE-2023-4482122Monitor
Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory
MediumCVSS 5.5No exploitEPSS 0%lcdf · gifsicleOct 9, 2023