Saitoha
Saitoha Libsixel: vulnerabilities and CVEs
Saitoha Libsixel has 48 published vulnerabilities, 9 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.
CVEs48
Last 12 months9
Critical4
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44638 | Low (2.5) | 0.13% | — | May 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointer dereference… |
| CVE-2026-44637 | High (7.1) | 0.17% | — | May 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in… |
| CVE-2026-44636 | High (7.8) | 0.14% | — | May 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The… |
| CVE-2026-33023 | High (7.8) | 0.25% | — | Apr 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf()… |
| CVE-2026-33021 | High (7.3) | 0.21% | — | Apr 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the… |
| CVE-2026-33020 | High (7.1) | 0.22% | — | Apr 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c,… |
| CVE-2026-33019 | High (7.1) | 0.21% | — | Apr 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where… |
| CVE-2026-33018 | High (7) | 0.19% | — | Apr 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t… |
| CVE-2025-61146 | Medium (4) | 0.12% | — | Feb 23, 2026 | saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c. |
| CVE-2025-9300 | Low (1.9) | 0.25% | — | Aug 21, 2025 | A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based… |
| CVE-2022-29978 | Medium (6.5) | 1.0% | — | May 11, 2022 | There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file. |
| CVE-2022-29977 | Medium (6.5) | 1.0% | — | May 11, 2022 | There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file. |
| CVE-2022-27046 | High (8.8) | 1.0% | — | Apr 8, 2022 | libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388. |
| CVE-2022-27044 | High (8.8) | 1.0% | — | Apr 8, 2022 | libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876. |
| CVE-2022-27938 | Medium (5.5) | 0.61% | — | Mar 26, 2022 | stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw. |
| CVE-2021-46700 | Medium (6.5) | 0.82% | — | Feb 19, 2022 | In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free. |
| CVE-2020-21548 | High (8.8) | 1.1% | — | Sep 17, 2021 | Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c. |
| CVE-2020-21547 | High (8.8) | 1.1% | — | Sep 17, 2021 | Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c. |
| CVE-2020-21050 | Medium (6.5) | 1.6% | — | Sep 14, 2021 | Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c. |
| CVE-2020-21049 | Medium (6.5) | 1.4% | — | Sep 14, 2021 | An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file. |
| CVE-2020-21048 | Medium (6.5) | 1.4% | — | Sep 14, 2021 | An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file. |
| CVE-2020-21677 | Medium (6.5) | 0.90% | — | Aug 10, 2021 | A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format. |
| CVE-2020-36120 | High (7.5) | 1.2% | — | Apr 14, 2021 | Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS). |
| CVE-2020-19668 | Medium (6.5) | 0.86% | — | Nov 20, 2020 | Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6. |
| CVE-2020-11721 | Medium (6.5) | 0.94% | — | Apr 12, 2020 | load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service. |
| CVE-2019-20205 | High (8.8) | 1.0% | — | Jan 2, 2020 | libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c. |
| CVE-2019-20140 | High (8.8) | 1.1% | — | Dec 30, 2019 | An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c. |
| CVE-2019-20094 | High (8.8) | 1.0% | — | Dec 30, 2019 | An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c. |
| CVE-2019-20024 | Medium (6.5) | 0.99% | — | Dec 27, 2019 | A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4. |
| CVE-2019-20023 | Medium (6.5) | 0.99% | — | Dec 27, 2019 | A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4. |