Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-14232 | The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and a The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif file. NVD description · AI analysis pending | 5.5 | 1% |
| — | ||
| CVE-2019-14373 | An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a heap-based buffer over-read in libpng via a crafted flif file. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2018-14876 | An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a longjmp that leads to an uninitialized stack frame after a libpng error concerning the IHDR image width. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2018-12109 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC ::process function in transform/palette_C.hpp allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PAM image file. NVD description · AI analysis pending | 7.8 | 1% | PoC |
| — | |
| CVE-2018-11507 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long loop in image_load_pnm in image/image-pnm.cpp. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2018-10972 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC::process function in transform/palette_C.hpp allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted file. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2018-10971 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote attackers to cause a denial of service (attempted excessive memory allocation) via a crafted file. NVD description · AI analysis pending | 5.5 | 1% |
| — |