libvips records
20 published records for vendor libvips.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 95%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-122 Heap-based Buffer Overflow3
- CWE-190 Integer Overflow or Wraparound2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-369 Divide By Zero1
- CWE-404 Improper Resource Shutdown or Release1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2019-17534No exploit | vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, lelibvips · libvips · CWE-416 | High8.8 | — | 2.4% | Oct 12, 2019 |
34Monitor | CVE-2025-29769No exploit | libvips has a potential heap-based buffer overflow when attempting to convert multiband TIFF input to HEIF outputlibvips · libvips · CWE-122 | High8.5 | — | 0.3% | Apr 7, 2025 |
31Monitor | CVE-2018-7998No exploit | In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, whichlibvips · libvips · CWE-362 | High7.5 | — | 1.8% | Mar 9, 2018 |
28Monitor | CVE-2026-35591No exploit | Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tilelibvips · libvips · CWE-122 | High7.0 | — | 0.2% | Jul 20, 2026 |
28Monitor | CVE-2026-33327No exploit | Possible integer overflow leading to potential heap-based buffer overflowlibvips · libvips · CWE-190 | High7.0 | — | 0.2% | Jul 20, 2026 |
27Monitor | CVE-2026-35590No exploit | Possible out-of-bounds read leading to crash when decoding well-crafted EXIF metadatalibvips · libvips · CWE-122 | Medium6.8 | — | 0.2% | Jul 20, 2026 |
27Monitor | CVE-2026-33328No exploit | Possible integer overflow on 32-bit systems when reading GIF imageslibvips · libvips · CWE-190 | Medium6.8 | — | 0.2% | Jul 20, 2026 |
26Monitor | CVE-2021-27847No exploit | Division-By-Zero vulnerability in Libvips 8.10.5 in the function vips_eye_point, eye.c#L83, and function vips_mask_point, mask.c#L85.libvips · libvips · CWE-369 | Medium6.5 | — | 1.0% | Jul 15, 2021 |
22Monitor | CVE-2019-6976No exploit | libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/libvips · libvips · CWE-908 | Medium5.3 | — | 2.3% | Jan 26, 2019 |
22Monitor | CVE-2020-20739No exploit | im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of libvips · libvips · CWE-909 | Medium5.3 | — | 2.0% | Nov 20, 2020 |
22Monitor | CVE-2023-40032No exploit | Potential segfault due to NULL pointer dereference in libvipslibvips · libvips · CWE-476 | Medium5.5 | — | 0.3% | Sep 11, 2023 |
20Monitor | CVE-2025-59933No exploit | libvips is vulnerable to Buffer Over-Read in poppler-based pdfloadlibvips · libvips · CWE-126 | Medium5.1 | — | 0.2% | Sep 29, 2025 |
19Monitor | CVE-2026-3145No exploit | libvips matrixload.c vips_foreign_load_matrix_header memory corruptionlibvips · libvips · CWE-119 | Medium4.8 | — | 0.2% | Feb 24, 2026 |
19Monitor | CVE-2026-3146No exploit | libvips matrixload.c vips_foreign_load_matrix_header null pointer dereferencelibvips · libvips · CWE-404 | Medium4.8 | — | 0.2% | Feb 24, 2026 |
7Monitor | CVE-2026-3147No exploit | libvips csvload.c vips_foreign_load_csv_build heap-based overflowlibvips · libvips · CWE-119 | Low1.9 | — | 0.2% | Feb 25, 2026 |
7Monitor | CVE-2026-3281No exploit | libvips bandrank.c vips_bandrank_build heap-based overflowlibvips · libvips · CWE-119 | Low1.9 | — | 0.2% | Feb 26, 2026 |
7Monitor | CVE-2026-3283No exploit | libvips extract.c vips_extract_band_build out-of-boundslibvips · libvips · CWE-119 | Low1.9 | — | 0.2% | Feb 26, 2026 |
7Monitor | CVE-2026-3282No exploit | libvips unpremultiply.c vips_unpremultiply_build out-of-boundslibvips · libvips · CWE-119 | Low1.9 | — | 0.2% | Feb 26, 2026 |
7Monitor | CVE-2026-3284No exploit | libvips extract.c vips_extract_area_build integer overflowlibvips · libvips · CWE-189 | Low1.9 | — | 0.2% | Feb 26, 2026 |
4Monitor | CVE-2026-2913No exploit | libvips source.c vips_source_read_to_memory heap-based overflowlibvips · libvips · CWE-119 | Low1.1 | — | 0.2% | Feb 22, 2026 |
- CVE-2019-1753436Monitor
vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, le
HighCVSS 8.8No exploitEPSS 2%libvips · libvipsOct 12, 2019
- CVE-2025-2976934Monitor
libvips has a potential heap-based buffer overflow when attempting to convert multiband TIFF input to HEIF output
HighCVSS 8.5No exploitEPSS 0%libvips · libvipsApr 7, 2025
- CVE-2018-799831Monitor
In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which
HighCVSS 7.5No exploitEPSS 2%libvips · libvipsMar 9, 2018
- CVE-2026-3559128Monitor
Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile
HighCVSS 7.0No exploitEPSS 0%libvips · libvipsJul 20, 2026
- CVE-2026-3332728Monitor
Possible integer overflow leading to potential heap-based buffer overflow
HighCVSS 7.0No exploitEPSS 0%libvips · libvipsJul 20, 2026
- CVE-2026-3559027Monitor
Possible out-of-bounds read leading to crash when decoding well-crafted EXIF metadata
MediumCVSS 6.8No exploitEPSS 0%libvips · libvipsJul 20, 2026
- CVE-2026-3332827Monitor
Possible integer overflow on 32-bit systems when reading GIF images
MediumCVSS 6.8No exploitEPSS 0%libvips · libvipsJul 20, 2026
- CVE-2021-2784726Monitor
Division-By-Zero vulnerability in Libvips 8.10.5 in the function vips_eye_point, eye.c#L83, and function vips_mask_point, mask.c#L85.
MediumCVSS 6.5No exploitEPSS 1%libvips · libvipsJul 15, 2021
- CVE-2019-697622Monitor
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/
MediumCVSS 5.3No exploitEPSS 2%libvips · libvipsJan 26, 2019
- CVE-2020-2073922Monitor
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of
MediumCVSS 5.3No exploitEPSS 2%libvips · libvipsNov 20, 2020
- CVE-2023-4003222Monitor
Potential segfault due to NULL pointer dereference in libvips
MediumCVSS 5.5No exploitEPSS 0%libvips · libvipsSep 11, 2023
- CVE-2025-5993320Monitor
libvips is vulnerable to Buffer Over-Read in poppler-based pdfload
MediumCVSS 5.1No exploitEPSS 0%libvips · libvipsSep 29, 2025
- CVE-2026-314519Monitor
libvips matrixload.c vips_foreign_load_matrix_header memory corruption
MediumCVSS 4.8No exploitEPSS 0%libvips · libvipsFeb 24, 2026
- CVE-2026-314619Monitor
libvips matrixload.c vips_foreign_load_matrix_header null pointer dereference
MediumCVSS 4.8No exploitEPSS 0%libvips · libvipsFeb 24, 2026
- CVE-2026-31477Monitor
libvips csvload.c vips_foreign_load_csv_build heap-based overflow
LowCVSS 1.9No exploitEPSS 0%libvips · libvipsFeb 25, 2026
- CVE-2026-32817Monitor
libvips bandrank.c vips_bandrank_build heap-based overflow
LowCVSS 1.9No exploitEPSS 0%libvips · libvipsFeb 26, 2026
- CVE-2026-32837Monitor
libvips extract.c vips_extract_band_build out-of-bounds
LowCVSS 1.9No exploitEPSS 0%libvips · libvipsFeb 26, 2026
- CVE-2026-32827Monitor
libvips unpremultiply.c vips_unpremultiply_build out-of-bounds
LowCVSS 1.9No exploitEPSS 0%libvips · libvipsFeb 26, 2026
- CVE-2026-32847Monitor
libvips extract.c vips_extract_area_build integer overflow
LowCVSS 1.9No exploitEPSS 0%libvips · libvipsFeb 26, 2026
- CVE-2026-29134Monitor
libvips source.c vips_source_read_to_memory heap-based overflow
LowCVSS 1.1No exploitEPSS 0%libvips · libvipsFeb 22, 2026