Saitoha / Libsixel
48 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44637 | libsixel: integer overflow in parser | HIGH | 7.1 | May 14, 2026 |
| CVE-2026-44636 | libsixel: integer overflow in encoder | HIGH | 7.8 | May 14, 2026 |
| CVE-2026-44638 | libsixel: NULL pointer dereference | LOW | 2.5 | May 14, 2026 |
| CVE-2026-33023 | libsixel: Use-after-free in load_with_gdkpixbuf() | HIGH | 7.8 | Apr 14, 2026 |
| CVE-2026-33021 | libsixel: Use-after-free in sixel_encoder_encode_bytes() | HIGH | 7.3 | Apr 14, 2026 |
| CVE-2026-33020 | libsixel: Integer Overflow in write_png_to_file() leads to Heap-based Buffer Overflow | HIGH | 7.1 | Apr 14, 2026 |
| CVE-2026-33019 | libsixel: Integer overflow leads to Out-of-bounds Read in img2sixel | HIGH | 7.1 | Apr 14, 2026 |
| CVE-2026-33018 | libsixel: Use-After-Free in load_gif() | HIGH | 7.0 | Apr 14, 2026 |
| CVE-2025-61146 | saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c. | MEDIUM | 4.0 | Feb 23, 2026 |
| CVE-2025-9300 | saitoha libsixel img2sixel encoder.c sixel_debug_print_palette stack-based overflow | MEDIUM | 4.8 | Aug 21, 2025 |
| CVE-2022-29978 | There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerabi… | MEDIUM | 6.5 | May 11, 2022 |
| CVE-2022-29977 | There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability… | MEDIUM | 6.5 | May 11, 2022 |
| CVE-2022-27044 | libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876. | HIGH | 8.8 | Apr 8, 2022 |
| CVE-2022-27046 | libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388. | HIGH | 8.8 | Apr 8, 2022 |
| CVE-2022-27938 | stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw. | MEDIUM | 5.5 | Mar 26, 2022 |
| CVE-2021-46700 | In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free. | MEDIUM | 6.5 | Feb 19, 2022 |
| CVE-2020-21548 | Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c. | HIGH | 8.8 | Sep 17, 2021 |
| CVE-2020-21547 | Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c. | HIGH | 8.8 | Sep 17, 2021 |
| CVE-2020-21050 | Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c. | MEDIUM | 6.5 | Sep 14, 2021 |
| CVE-2020-21049 | An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file. | MEDIUM | 6.5 | Sep 14, 2021 |
| CVE-2020-21048 | An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file. | MEDIUM | 6.5 | Sep 14, 2021 |
| CVE-2020-21677 | A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (D… | MEDIUM | 6.5 | Aug 10, 2021 |
| CVE-2020-36120 | Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS). | HIGH | 7.5 | Apr 14, 2021 |
| CVE-2020-19668 | Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6. | MEDIUM | 6.5 | Nov 20, 2020 |
| CVE-2020-11721 | load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service. | MEDIUM | 6.5 | Apr 12, 2020 |
Showing 1 to 25 of 48 CVEs