Записи LibRaw
65 опубликованных записей вендора libraw.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 96,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read13
- CWE-787 Out-of-bounds Write11
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-190 Integer Overflow or Wraparound7
- CWE-476 NULL Pointer Dereference6
- CWE-400 Uncontrolled Resource Consumption2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
65 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2015-8367Эксплойта нет | The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related libraw · libraw · CWE-665 | Критическая9,8 | — | 5,6 % | 14 янв. 2020 г. |
41В плане | CVE-2015-8366Эксплойта нет | Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and posslibraw · libraw · CWE-129 | Критическая9,8 | — | 5,1 % | 14 янв. 2020 г. |
40В плане | CVE-2017-14265Эксплойта нет | A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3.libraw · libraw · CWE-119 | Критическая9,8 | — | 4,3 % | 11 сент. 2017 г. |
40В плане | CVE-2017-6886Эксплойта нет | An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memlibraw · libraw · CWE-119 | Критическая9,8 | — | 3,4 % | 16 мая 2017 г. |
39Наблюдать | CVE-2017-6889Эксплойта нет | An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploilibraw · libraw-demosaic-pack-gpl2 · CWE-190 | Критическая9,8 | — | 1,5 % | 15 мая 2017 г. |
39Наблюдать | CVE-2017-6890Эксплойта нет | A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 belibraw · libraw-demosaic-pack-gpl2 · CWE-119 | Критическая9,8 | — | 1,5 % | 15 мая 2017 г. |
39Наблюдать | CVE-2026-21413Эксплойта нет | A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b.libraw · libraw · CWE-129 | Критическая9,8 | — | 0,9 % | 7 апр. 2026 г. |
39Наблюдать | CVE-2026-20889Эксплойта нет | A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b.libraw · libraw · CWE-190 | Критическая9,8 | — | 0,8 % | 7 апр. 2026 г. |
39Наблюдать | CVE-2026-20911Эксплойта нет | A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b.libraw · libraw · CWE-131 | Критическая9,8 | — | 0,6 % | 7 апр. 2026 г. |
39Наблюдать | CVE-2026-24450Эксплойта нет | An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2.libraw · libraw · CWE-190 | Критическая9,8 | — | 0,6 % | 7 апр. 2026 г. |
39Наблюдать | CVE-2026-20884Эксплойта нет | An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2.libraw · libraw · CWE-190 | Критическая9,8 | — | 0,6 % | 7 апр. 2026 г. |
39Наблюдать | CVE-2025-43964Эксплойта нет | In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.libraw · libraw · CWE-1284 | Критическая9,8 | — | 0,4 % | 20 апр. 2025 г. |
37Наблюдать | CVE-2017-14608Эксплойта нет | In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_clibraw · libraw · CWE-125 | Критическая9,1 | — | 2,1 % | 20 сент. 2017 г. |
36Наблюдать | CVE-2018-5808Эксплойта нет | An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stacklibraw · libraw · CWE-787 | Высокая8,8 | — | 2,8 % | 7 дек. 2018 г. |
36Наблюдать | CVE-2018-5809Эксплойта нет | An error within the "LibRaw::parse_exif()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to causelibraw · libraw · CWE-787 | Высокая8,8 | — | 2,8 % | 7 дек. 2018 г. |
36Наблюдать | CVE-2018-10528Эксплойта нет | An issue was discovered in LibRaw 0.18.9.libraw · libraw · CWE-787 | Высокая8,8 | — | 2,5 % | 28 апр. 2018 г. |
36Наблюдать | CVE-2017-14348Эксплойта нет | LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file.libraw · libraw · CWE-119 | Высокая8,8 | — | 2,1 % | 12 сент. 2017 г. |
36Наблюдать | CVE-2018-5810Эксплойта нет | An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a libraw · libraw · CWE-787 | Высокая8,8 | — | 2,1 % | 7 дек. 2018 г. |
36Наблюдать | CVE-2018-20337Эксплойта нет | There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1.libraw · libraw · CWE-787 | Высокая8,8 | — | 2,1 % | 21 дек. 2018 г. |
36Наблюдать | CVE-2017-16909Эксплойта нет | An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to calibraw · libraw · CWE-119 | Высокая8,8 | — | 2,0 % | 7 дек. 2018 г. |
36Наблюдать | CVE-2018-5805Эксплойта нет | A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploilibraw · libraw · CWE-787 | Высокая8,8 | — | 2,0 % | 7 дек. 2018 г. |
36Наблюдать | CVE-2018-5807Эксплойта нет | An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause alibraw · libraw · CWE-125 | Высокая8,8 | — | 2,0 % | 7 дек. 2018 г. |
36Наблюдать | CVE-2018-5802Эксплойта нет | An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0libraw · libraw · CWE-125 | Высокая8,8 | — | 2,0 % | 7 дек. 2018 г. |
36Наблюдать | CVE-2018-10529Эксплойта нет | An issue was discovered in LibRaw 0.18.9.libraw · libraw · CWE-125 | Высокая8,8 | — | 1,9 % | 28 апр. 2018 г. |
36Наблюдать | CVE-2025-43963Эксплойта нет | In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values alibraw · libraw · CWE-125 | Критическая9,1 | — | 0,4 % | 20 апр. 2025 г. |
- CVE-2015-836741В плане
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %libraw · libraw14 янв. 2020 г.
- CVE-2015-836641В плане
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and poss
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %libraw · libraw14 янв. 2020 г.
- CVE-2017-1426540В плане
A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %libraw · libraw11 сент. 2017 г.
- CVE-2017-688640В плане
An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt mem
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libraw · libraw16 мая 2017 г.
- CVE-2017-688939Наблюдать
An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libraw · libraw-demosaic-pack-gpl215 мая 2017 г.
- CVE-2017-689039Наблюдать
A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 be
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libraw · libraw-demosaic-pack-gpl215 мая 2017 г.
- CVE-2026-2141339Наблюдать
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libraw · libraw7 апр. 2026 г.
- CVE-2026-2088939Наблюдать
A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libraw · libraw7 апр. 2026 г.
- CVE-2026-2091139Наблюдать
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libraw · libraw7 апр. 2026 г.
- CVE-2026-2445039Наблюдать
An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libraw · libraw7 апр. 2026 г.
- CVE-2026-2088439Наблюдать
An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libraw · libraw7 апр. 2026 г.
- CVE-2025-4396439Наблюдать
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %libraw · libraw20 апр. 2025 г.
- CVE-2017-1460837Наблюдать
In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_c
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %libraw · libraw20 сент. 2017 г.
- CVE-2018-580836Наблюдать
An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %libraw · libraw7 дек. 2018 г.
- CVE-2018-580936Наблюдать
An error within the "LibRaw::parse_exif()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %libraw · libraw7 дек. 2018 г.
- CVE-2018-1052836Наблюдать
An issue was discovered in LibRaw 0.18.9.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libraw · libraw28 апр. 2018 г.
- CVE-2017-1434836Наблюдать
LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libraw · libraw12 сент. 2017 г.
- CVE-2018-581036Наблюдать
An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libraw · libraw7 дек. 2018 г.
- CVE-2018-2033736Наблюдать
There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libraw · libraw21 дек. 2018 г.
- CVE-2017-1690936Наблюдать
An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to ca
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libraw · libraw7 дек. 2018 г.
- CVE-2018-580536Наблюдать
A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploi
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libraw · libraw7 дек. 2018 г.
- CVE-2018-580736Наблюдать
An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libraw · libraw7 дек. 2018 г.
- CVE-2018-580236Наблюдать
An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libraw · libraw7 дек. 2018 г.
- CVE-2018-1052936Наблюдать
An issue was discovered in LibRaw 0.18.9.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libraw · libraw28 апр. 2018 г.
- CVE-2025-4396336Наблюдать
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values a
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %libraw · libraw20 апр. 2025 г.