LibRaw records
65 published records for vendor libraw.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 96.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read13
- CWE-787 Out-of-bounds Write11
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-190 Integer Overflow or Wraparound7
- CWE-476 NULL Pointer Dereference6
- CWE-400 Uncontrolled Resource Consumption2
The weakness classes this vendor ships most often: where to look.
CWEAll records
65 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2015-8367No exploit | The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related libraw · libraw · CWE-665 | Critical9.8 | — | 5.6% | Jan 14, 2020 |
41Plan | CVE-2015-8366No exploit | Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and posslibraw · libraw · CWE-129 | Critical9.8 | — | 5.1% | Jan 14, 2020 |
40Plan | CVE-2017-14265No exploit | A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3.libraw · libraw · CWE-119 | Critical9.8 | — | 4.3% | Sep 11, 2017 |
40Plan | CVE-2017-6886No exploit | An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memlibraw · libraw · CWE-119 | Critical9.8 | — | 3.4% | May 16, 2017 |
39Monitor | CVE-2017-6889No exploit | An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploilibraw · libraw-demosaic-pack-gpl2 · CWE-190 | Critical9.8 | — | 1.5% | May 15, 2017 |
39Monitor | CVE-2017-6890No exploit | A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 belibraw · libraw-demosaic-pack-gpl2 · CWE-119 | Critical9.8 | — | 1.5% | May 15, 2017 |
39Monitor | CVE-2026-21413No exploit | A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b.libraw · libraw · CWE-129 | Critical9.8 | — | 0.9% | Apr 7, 2026 |
39Monitor | CVE-2026-20889No exploit | A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b.libraw · libraw · CWE-190 | Critical9.8 | — | 0.8% | Apr 7, 2026 |
39Monitor | CVE-2026-20911No exploit | A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b.libraw · libraw · CWE-131 | Critical9.8 | — | 0.6% | Apr 7, 2026 |
39Monitor | CVE-2026-24450No exploit | An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2.libraw · libraw · CWE-190 | Critical9.8 | — | 0.6% | Apr 7, 2026 |
39Monitor | CVE-2026-20884No exploit | An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2.libraw · libraw · CWE-190 | Critical9.8 | — | 0.6% | Apr 7, 2026 |
39Monitor | CVE-2025-43964No exploit | In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.libraw · libraw · CWE-1284 | Critical9.8 | — | 0.4% | Apr 20, 2025 |
37Monitor | CVE-2017-14608No exploit | In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_clibraw · libraw · CWE-125 | Critical9.1 | — | 2.1% | Sep 20, 2017 |
36Monitor | CVE-2018-5808No exploit | An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stacklibraw · libraw · CWE-787 | High8.8 | — | 2.8% | Dec 7, 2018 |
36Monitor | CVE-2018-5809No exploit | An error within the "LibRaw::parse_exif()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to causelibraw · libraw · CWE-787 | High8.8 | — | 2.8% | Dec 7, 2018 |
36Monitor | CVE-2018-10528No exploit | An issue was discovered in LibRaw 0.18.9.libraw · libraw · CWE-787 | High8.8 | — | 2.5% | Apr 28, 2018 |
36Monitor | CVE-2017-14348No exploit | LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file.libraw · libraw · CWE-119 | High8.8 | — | 2.1% | Sep 12, 2017 |
36Monitor | CVE-2018-5810No exploit | An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a libraw · libraw · CWE-787 | High8.8 | — | 2.1% | Dec 7, 2018 |
36Monitor | CVE-2018-20337No exploit | There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1.libraw · libraw · CWE-787 | High8.8 | — | 2.1% | Dec 21, 2018 |
36Monitor | CVE-2017-16909No exploit | An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to calibraw · libraw · CWE-119 | High8.8 | — | 2.0% | Dec 7, 2018 |
36Monitor | CVE-2018-5805No exploit | A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploilibraw · libraw · CWE-787 | High8.8 | — | 2.0% | Dec 7, 2018 |
36Monitor | CVE-2018-5807No exploit | An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause alibraw · libraw · CWE-125 | High8.8 | — | 2.0% | Dec 7, 2018 |
36Monitor | CVE-2018-5802No exploit | An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0libraw · libraw · CWE-125 | High8.8 | — | 2.0% | Dec 7, 2018 |
36Monitor | CVE-2018-10529No exploit | An issue was discovered in LibRaw 0.18.9.libraw · libraw · CWE-125 | High8.8 | — | 1.9% | Apr 28, 2018 |
36Monitor | CVE-2025-43963No exploit | In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values alibraw · libraw · CWE-125 | Critical9.1 | — | 0.4% | Apr 20, 2025 |
- CVE-2015-836741Plan
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related
CriticalCVSS 9.8No exploitEPSS 6%libraw · librawJan 14, 2020
- CVE-2015-836641Plan
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and poss
CriticalCVSS 9.8No exploitEPSS 5%libraw · librawJan 14, 2020
- CVE-2017-1426540Plan
A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3.
CriticalCVSS 9.8No exploitEPSS 4%libraw · librawSep 11, 2017
- CVE-2017-688640Plan
An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt mem
CriticalCVSS 9.8No exploitEPSS 3%libraw · librawMay 16, 2017
- CVE-2017-688939Monitor
An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploi
CriticalCVSS 9.8No exploitEPSS 1%libraw · libraw-demosaic-pack-gpl2May 15, 2017
- CVE-2017-689039Monitor
A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 be
CriticalCVSS 9.8No exploitEPSS 1%libraw · libraw-demosaic-pack-gpl2May 15, 2017
- CVE-2026-2141339Monitor
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b.
CriticalCVSS 9.8No exploitEPSS 1%libraw · librawApr 7, 2026
- CVE-2026-2088939Monitor
A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b.
CriticalCVSS 9.8No exploitEPSS 1%libraw · librawApr 7, 2026
- CVE-2026-2091139Monitor
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b.
CriticalCVSS 9.8No exploitEPSS 1%libraw · librawApr 7, 2026
- CVE-2026-2445039Monitor
An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2.
CriticalCVSS 9.8No exploitEPSS 1%libraw · librawApr 7, 2026
- CVE-2026-2088439Monitor
An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2.
CriticalCVSS 9.8No exploitEPSS 1%libraw · librawApr 7, 2026
- CVE-2025-4396439Monitor
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
CriticalCVSS 9.8No exploitEPSS 0%libraw · librawApr 20, 2025
- CVE-2017-1460837Monitor
In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_c
CriticalCVSS 9.1No exploitEPSS 2%libraw · librawSep 20, 2017
- CVE-2018-580836Monitor
An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack
HighCVSS 8.8No exploitEPSS 3%libraw · librawDec 7, 2018
- CVE-2018-580936Monitor
An error within the "LibRaw::parse_exif()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause
HighCVSS 8.8No exploitEPSS 3%libraw · librawDec 7, 2018
- CVE-2018-1052836Monitor
An issue was discovered in LibRaw 0.18.9.
HighCVSS 8.8No exploitEPSS 2%libraw · librawApr 28, 2018
- CVE-2017-1434836Monitor
LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file.
HighCVSS 8.8No exploitEPSS 2%libraw · librawSep 12, 2017
- CVE-2018-581036Monitor
An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a
HighCVSS 8.8No exploitEPSS 2%libraw · librawDec 7, 2018
- CVE-2018-2033736Monitor
There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1.
HighCVSS 8.8No exploitEPSS 2%libraw · librawDec 21, 2018
- CVE-2017-1690936Monitor
An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to ca
HighCVSS 8.8No exploitEPSS 2%libraw · librawDec 7, 2018
- CVE-2018-580536Monitor
A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploi
HighCVSS 8.8No exploitEPSS 2%libraw · librawDec 7, 2018
- CVE-2018-580736Monitor
An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a
HighCVSS 8.8No exploitEPSS 2%libraw · librawDec 7, 2018
- CVE-2018-580236Monitor
An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0
HighCVSS 8.8No exploitEPSS 2%libraw · librawDec 7, 2018
- CVE-2018-1052936Monitor
An issue was discovered in LibRaw 0.18.9.
HighCVSS 8.8No exploitEPSS 2%libraw · librawApr 28, 2018
- CVE-2025-4396336Monitor
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values a
CriticalCVSS 9.1No exploitEPSS 0%libraw · librawApr 20, 2025