Skip to content
Noroxi

LibRaw records

65 published records for vendor libraw.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
6
With a fix record
96.9%
Median publish → KEV
No record has entered KEV

All records

65 records
  • The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related

    CriticalCVSS 9.8No exploitEPSS 6%

    libraw · librawJan 14, 2020

  • Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and poss

    CriticalCVSS 9.8No exploitEPSS 5%

    libraw · librawJan 14, 2020

  • A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3.

    CriticalCVSS 9.8No exploitEPSS 4%

    libraw · librawSep 11, 2017

  • An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt mem

    CriticalCVSS 9.8No exploitEPSS 3%

    libraw · librawMay 16, 2017

  • CVE-2017-6889
    39Monitor

    An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploi

    CriticalCVSS 9.8No exploitEPSS 1%

    libraw · libraw-demosaic-pack-gpl2May 15, 2017

  • CVE-2017-6890
    39Monitor

    A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 be

    CriticalCVSS 9.8No exploitEPSS 1%

    libraw · libraw-demosaic-pack-gpl2May 15, 2017

  • A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b.

    CriticalCVSS 9.8No exploitEPSS 1%

    libraw · librawApr 7, 2026

  • A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b.

    CriticalCVSS 9.8No exploitEPSS 1%

    libraw · librawApr 7, 2026

  • A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b.

    CriticalCVSS 9.8No exploitEPSS 1%

    libraw · librawApr 7, 2026

  • An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2.

    CriticalCVSS 9.8No exploitEPSS 1%

    libraw · librawApr 7, 2026

  • An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2.

    CriticalCVSS 9.8No exploitEPSS 1%

    libraw · librawApr 7, 2026

  • In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

    CriticalCVSS 9.8No exploitEPSS 0%

    libraw · librawApr 20, 2025

  • In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_c

    CriticalCVSS 9.1No exploitEPSS 2%

    libraw · librawSep 20, 2017

  • CVE-2018-5808
    36Monitor

    An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack

    HighCVSS 8.8No exploitEPSS 3%

    libraw · librawDec 7, 2018

  • CVE-2018-5809
    36Monitor

    An error within the "LibRaw::parse_exif()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause

    HighCVSS 8.8No exploitEPSS 3%

    libraw · librawDec 7, 2018

  • An issue was discovered in LibRaw 0.18.9.

    HighCVSS 8.8No exploitEPSS 2%

    libraw · librawApr 28, 2018

  • LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file.

    HighCVSS 8.8No exploitEPSS 2%

    libraw · librawSep 12, 2017

  • CVE-2018-5810
    36Monitor

    An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a

    HighCVSS 8.8No exploitEPSS 2%

    libraw · librawDec 7, 2018

  • There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1.

    HighCVSS 8.8No exploitEPSS 2%

    libraw · librawDec 21, 2018

  • An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to ca

    HighCVSS 8.8No exploitEPSS 2%

    libraw · librawDec 7, 2018

  • CVE-2018-5805
    36Monitor

    A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploi

    HighCVSS 8.8No exploitEPSS 2%

    libraw · librawDec 7, 2018

  • CVE-2018-5807
    36Monitor

    An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a

    HighCVSS 8.8No exploitEPSS 2%

    libraw · librawDec 7, 2018

  • CVE-2018-5802
    36Monitor

    An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0

    HighCVSS 8.8No exploitEPSS 2%

    libraw · librawDec 7, 2018

  • An issue was discovered in LibRaw 0.18.9.

    HighCVSS 8.8No exploitEPSS 2%

    libraw · librawApr 28, 2018

  • In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values a

    CriticalCVSS 9.1No exploitEPSS 0%

    libraw · librawApr 20, 2025