Vulnerabilities > Libraw > High

DATE CVE VULNERABILITY TITLE RISK
2023-02-17 CVE-2021-32142 Out-of-bounds Write vulnerability in Libraw 0.20.0
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
local
low complexity
libraw CWE-787
7.8
2021-06-02 CVE-2020-24870 Out-of-bounds Write vulnerability in Libraw
Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
network
low complexity
libraw CWE-787
8.8
2020-09-16 CVE-2020-24889 Classic Buffer Overflow vulnerability in Libraw
A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.
local
low complexity
libraw CWE-120
7.8
2020-07-02 CVE-2020-15503 Improper Input Validation vulnerability in multiple products
LibRaw before 0.20-RC1 lacks a thumbnail size range check.
network
low complexity
libraw fedoraproject debian CWE-20
7.5
2019-02-20 CVE-2018-5819 Resource Exhaustion vulnerability in multiple products
An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.
network
low complexity
libraw debian CWE-400
7.5
2019-02-20 CVE-2018-5818 Infinite Loop vulnerability in multiple products
An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop.
network
low complexity
libraw debian CWE-835
7.5
2019-02-20 CVE-2018-5817 Incorrect Type Conversion or Cast vulnerability in multiple products
A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_common.cpp) can be exploited to trigger an infinite loop.
network
low complexity
libraw debian CWE-704
7.5
2018-12-21 CVE-2018-20337 Out-of-bounds Write vulnerability in Libraw 0.19.1
There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1.
network
low complexity
libraw CWE-787
8.8
2018-12-07 CVE-2018-5810 Out-of-bounds Write vulnerability in multiple products
An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
network
low complexity
libraw canonical CWE-787
8.8
2018-12-07 CVE-2018-5809 Out-of-bounds Write vulnerability in Libraw
An error within the "LibRaw::parse_exif()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack-based buffer overflow and subsequently execute arbitrary code.
network
low complexity
libraw CWE-787
8.8