Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libraw CRITICAL 9.8
CVE-2026-24450

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious fi…

Mitigation only
Fix from $2,300 2026-04-07
Libraw HIGH 8.1
CVE-2026-24660

A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file …

No fix yet
Fix from $1,950 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-20884

An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can l…

Mitigation only
Fix from $2,300 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-20889

A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file …

Mitigation only
Fix from $2,300 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-20911

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially cr…

Mitigation only
Fix from $2,300 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-21413

A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A speciall…

Mitigation only
Fix from $2,300 2026-04-07
Libraw MEDIUM 5.3
CVE-2026-5342

A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw…

Fix: 0.22.1+
Fix from $1,600 2026-04-02
Libraw CRITICAL 9.8
CVE-2025-43964

In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

Fix: 0.21.4+
Fix from $2,300 2025-04-21
Libraw CRITICAL 9.1
CVE-2025-43962

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 v…

Fix: 0.21.4+
Fix from $2,300 2025-04-21
Libraw CRITICAL 9.1
CVE-2025-43963

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not ch…

Fix: 0.21.4+
Fix from $2,300 2025-04-21
Libraw CRITICAL 9.1
CVE-2025-43961

In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.

Fix: 0.21.4+
Fix from $2,300 2025-04-21
Libraw MEDIUM 6.5
CVE-2020-22628

Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.

Fix: after 0.19.5
Fix from $1,600 2023-08-22
Libraw HIGH 7.8
CVE-2021-32142

Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) …

Patch available
Fix from $1,950 2023-02-17
Libraw MEDIUM 5.5
CVE-2020-35535

In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when processing s…

Patch available
Fix from $1,600 2022-09-01
Libraw MEDIUM 5.5
CVE-2020-35534

In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 fi…

Patch available
Fix from $1,600 2022-09-01
Libraw HIGH 8.8
CVE-2020-24870

Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.

Fix: 0.20.1+
Fix from $1,950 2021-06-02
Libraw HIGH 7.8
CVE-2020-24889

A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent…

Fix: 0.20.0+
Fix from $1,950 2020-09-16
Libraw MEDIUM 5.5
CVE-2020-24890

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary …

No fix yet
Fix from $1,600 2020-09-16
Libraw MEDIUM 6.5
CVE-2020-15365

LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_ni…

No fix yet
Fix from $1,600 2020-06-28
Libraw CRITICAL 9.8
CVE-2015-8366

Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly exec…

Fix: 0.17.1+
Fix from $2,300 2020-01-14
Libraw CRITICAL 9.8
CVE-2015-8367EPSS 5%

The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory…

Fix: 0.17.1+
Fix from $2,300 2020-01-14
Libraw MEDIUM 6.5
CVE-2018-20363

LibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.

Fix: after 0.19.1
Fix from $1,600 2018-12-22
Libraw MEDIUM 6.5
CVE-2018-20364

LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.

Fix: after 0.19.1
Fix from $1,600 2018-12-22
Libraw MEDIUM 6.5
CVE-2018-20365

LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow.

Fix: after 0.19.1
Fix from $1,600 2018-12-22
Libraw HIGH 8.8
CVE-2018-20337

There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of s…

Patch available
Fix from $1,950 2018-12-21
Libraw HIGH 8.8
CVE-2018-5809

An error within the "LibRaw::parse_exif()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack-…

Fix: 0.18.9+
Fix from $1,950 2018-12-07
Libraw MEDIUM 6.5
CVE-2018-5804

A type confusion error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a …

Fix: 0.18.8+
Fix from $1,600 2018-12-07
Libraw CRITICAL 9.1
CVE-2017-14608

In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp…

Fix: after 0.18.4
Fix from $2,300 2017-09-20
Libraw HIGH 8.8
CVE-2017-14348

LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file.

Fix: after 0.18.3
Fix from $1,950 2017-09-12
Libraw CRITICAL 9.8
CVE-2017-14265

A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote deni…

Fix: after 0.18.2
Fix from $2,300 2017-09-11