Total
45 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-27938 | 2 Libsixel, Saitoha | 2 Libsixel, Libsixel | 2026-04-24 | 4.3 MEDIUM | 5.5 MEDIUM |
| stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw. | |||||
| CVE-2025-9300 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 5.3 MEDIUM |
| A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is identified as 316c086e79d66b62c0c4bc66229ee894e4fdb7d1. Applying a patch is advised to resolve this issue. | |||||
| CVE-2020-21049 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 6.5 MEDIUM |
| An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file. | |||||
| CVE-2022-27046 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 6.8 MEDIUM | 8.8 HIGH |
| libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388. | |||||
| CVE-2019-20022 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 6.5 MEDIUM |
| An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3. | |||||
| CVE-2020-21050 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 6.5 MEDIUM |
| Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c. | |||||
| CVE-2019-20094 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 6.8 MEDIUM | 8.8 HIGH |
| An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c. | |||||
| CVE-2019-19637 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 7.5 HIGH | 9.8 CRITICAL |
| An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c. | |||||
| CVE-2018-19756 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 5.5 MEDIUM |
| There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of service. | |||||
| CVE-2020-11721 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 6.5 MEDIUM |
| load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service. | |||||
| CVE-2022-29977 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 6.5 MEDIUM |
| There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file. | |||||
| CVE-2020-21547 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 6.8 MEDIUM | 8.8 HIGH |
| Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c. | |||||
| CVE-2019-19635 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 7.5 HIGH | 9.8 CRITICAL |
| An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c. | |||||
| CVE-2018-19759 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 5.5 MEDIUM |
| There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service. | |||||
| CVE-2020-19668 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 6.5 MEDIUM |
| Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6. | |||||
| CVE-2019-3573 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 5.5 MEDIUM |
| In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png. | |||||
| CVE-2021-46700 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 6.5 MEDIUM |
| In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free. | |||||
| CVE-2020-21677 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 6.5 MEDIUM |
| A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format. | |||||
| CVE-2019-20023 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 4.3 MEDIUM | 6.5 MEDIUM |
| A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4. | |||||
| CVE-2022-27044 | 1 Saitoha | 1 Libsixel | 2026-04-24 | 6.8 MEDIUM | 8.8 HIGH |
| libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876. | |||||
