Vulnerabilities > Libsixel Project > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-04-12 CVE-2020-11721 Access of Uninitialized Pointer vulnerability in Libsixel Project Libsixel 1.8.6
load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.
network
low complexity
libsixel-project CWE-824
6.5
2019-12-27 CVE-2019-20024 Out-of-bounds Write vulnerability in Libsixel Project Libsixel
A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
network
low complexity
libsixel-project CWE-787
6.5
2019-12-27 CVE-2019-20023 Memory Leak vulnerability in Libsixel Project Libsixel
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
network
low complexity
libsixel-project CWE-401
6.5
2019-12-27 CVE-2019-20022 Operation on a Resource after Expiration or Release vulnerability in Libsixel Project Libsixel
An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
network
low complexity
libsixel-project CWE-672
6.5
2019-04-08 CVE-2019-11024 Uncontrolled Recursion vulnerability in Libsixel Project Libsixel 1.8.2
The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
local
low complexity
libsixel-project CWE-674
5.5
2019-01-02 CVE-2019-3573 Infinite Loop vulnerability in Libsixel Project Libsixel 1.8.2
In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.
local
low complexity
libsixel-project CWE-835
5.5
2018-11-30 CVE-2018-19763 Out-of-bounds Read vulnerability in Libsixel Project Libsixel 1.8.2
There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a denial of service.
local
low complexity
libsixel-project CWE-125
5.5
2018-11-30 CVE-2018-19761 Out-of-bounds Read vulnerability in Libsixel Project Libsixel 1.8.2
There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of service.
local
low complexity
libsixel-project CWE-125
5.5
2018-11-30 CVE-2018-19759 Out-of-bounds Read vulnerability in Libsixel Project Libsixel 1.8.2
There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.
local
low complexity
libsixel-project CWE-125
5.5
2018-11-30 CVE-2018-19757 NULL Pointer Dereference vulnerability in Libsixel Project Libsixel 1.8.2
There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.
network
low complexity
libsixel-project CWE-476
6.5