Skip to main content

Vendor/product archive

freeimage_project / freeimage CVEs

Beta · best-effort

53 CVEs tagged to freeimage_project / freeimage2 Critical, 22 High, 28 Medium, 1 Low, 0 Unrated.

CVE-2024-28563

Published Mar 20, 2024

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::DwaCompressor::Classifier::Clas…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28562

Published Mar 20, 2024

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::copyIntoFrameBuffer() component when rea…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47997

Published Jan 10, 2024

An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47996

Published Jan 9, 2024

An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a denial of service.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47995

Published Jan 9, 2024

Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 allows attackers to cause a denial of service.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47994

Published Jan 9, 2024

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service an…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47993

Published Jan 9, 2024

A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47992

Published Jan 9, 2024

An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24295

Published Aug 22, 2023

Buffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in FreeImage 3.19.0 [r1859] allows remote attackers to ru narbitrary code via use of crafted psd file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24294

Published Aug 22, 2023

Buffer Overflow vulnerability in psdParser::UnpackRLE function in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to cuase a denial of service via opening of cra…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24293

Published Aug 22, 2023

Buffer Overflow vulnerability in psdThumbnail::Read in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted psd file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24292

Published Aug 22, 2023

Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-22524

Published Aug 22, 2023

Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21428

Published Aug 22, 2023

Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-21427

Published Aug 22, 2023

Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-21426

Published Aug 22, 2023

Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted im…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12214

Published May 20, 2019

In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j2k.c. The value of l_N_ppm comes from the file read in, and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12212

Published May 20, 2019

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 53 CVEsPage 2 of 3