Freeimage Project
Freeimage Project Freeimage: vulnerabilidades y CVE
Freeimage Project Freeimage tiene 53 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE53
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-70968 | Crítica (9.8) | 0.51% | — | 14 ene 2026 | FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE(). |
| CVE-2025-65803 | Media (6.5) | 0.30% | — | 10 dic 2025 | An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted PSD file. |
| CVE-2024-9029 | Alta (7.5) | 0.51% | — | 27 sept 2024 | A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in the Source/Metadata/IPTC.cpp file because the size of the profile is not… |
| CVE-2024-31570 | Crítica (9.8) | 0.60% | — | 19 sept 2024 | libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file. |
| CVE-2024-28584 | Baja (3.3) | 0.41% | — | 20 mar 2024 | Null Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the J2KImageToFIBITMAP() function when reading images in J2K format. |
| CVE-2024-28583 | Alta (7.8) | 0.37% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the readLine() function when reading images in XPM format. |
| CVE-2024-28582 | Alta (8.4) | 0.36% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format. |
| CVE-2024-28581 | Alta (8.4) | 0.36% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format. |
| CVE-2024-28580 | Alta (8.4) | 0.36% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format. |
| CVE-2024-28579 | Media (6.2) | 0.29% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImage_Unload() function when reading images in HDR format. |
| CVE-2024-28578 | Alta (8.4) | 0.36% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in RAS format. |
| CVE-2024-28577 | Media (5.5) | 0.29% | — | 20 mar 2024 | Null Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the jpeg_read_exif_profile_raw() function when reading images in JPEG… |
| CVE-2024-28576 | Media (5.5) | 0.28% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_tcp_destroy() function when reading images in J2K format. |
| CVE-2024-28575 | Media (6.2) | 0.28% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_read_mct() function when reading images in J2K format. |
| CVE-2024-28574 | Media (6.2) | 0.29% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_copy_default_tcp_and_create_tcd() function when reading images in J2K… |
| CVE-2024-28573 | Media (6.2) | 0.29% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the jpeg_read_exif_profile() function when reading images in JPEG format. |
| CVE-2024-28572 | Media (6.2) | 0.28% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImage_SetTagValue() function when reading images in JPEG format. |
| CVE-2024-28571 | Media (5.5) | 0.28% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the fill_input_buffer() function when reading images in JPEG format. |
| CVE-2024-28570 | Media (5.5) | 0.28% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the processMakerNote() function when reading images in JPEG format. |
| CVE-2024-28569 | Alta (7.8) | 0.34% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in EXR format. |
| CVE-2024-28568 | Media (6.2) | 0.29% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the read_iptc_profile() function when reading images in TIFF format. |
| CVE-2024-28567 | Media (6.2) | 0.29% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImage_CreateICCProfile() function when reading images in TIFF format. |
| CVE-2024-28566 | Alta (8.4) | 0.36% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format. |
| CVE-2024-28565 | Media (5.5) | 0.43% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the psdParser::ReadImageData() function when reading images in PSD format. |
| CVE-2024-28564 | Media (6.2) | 0.46% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::CharPtrIO::readChars() function when reading images in EXR format. |
| CVE-2024-28563 | Media (5.9) | 0.46% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::DwaCompressor::Classifier::Classifier() function when reading images in… |
| CVE-2024-28562 | Media (6.8) | 0.47% | — | 20 mar 2024 | Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::copyIntoFrameBuffer() component when reading images in EXR format. |
| CVE-2023-47997 | Media (6.5) | 0.88% | — | 10 ene 2024 | An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service. |
| CVE-2023-47996 | Media (6.5) | 0.58% | — | 9 ene 2024 | An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a denial of service. |
| CVE-2023-47995 | Media (6.5) | 0.73% | — | 9 ene 2024 | Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 allows attackers to cause a denial of service. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.