« Back to list

Saitoha

Saitoha Libsixel: vulnerabilities and CVEs

Saitoha Libsixel has 48 published vulnerabilities, 9 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs48
Last 12 months9
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-44638Low (2.5)0.13%—May 14, 2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointer dereference…
CVE-2026-44637High (7.1)0.17%—May 14, 2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in…
CVE-2026-44636High (7.8)0.14%—May 14, 2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The…
CVE-2026-33023High (7.8)0.25%—Apr 14, 2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf()…
CVE-2026-33021High (7.3)0.21%—Apr 14, 2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the…
CVE-2026-33020High (7.1)0.22%—Apr 14, 2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c,…
CVE-2026-33019High (7.1)0.21%—Apr 14, 2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where…
CVE-2026-33018High (7)0.19%—Apr 14, 2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t…
CVE-2025-61146Medium (4)0.12%—Feb 23, 2026
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
CVE-2025-9300Low (1.9)0.25%—Aug 21, 2025
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based…
CVE-2022-29978Medium (6.5)1.0%—May 11, 2022
There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
CVE-2022-29977Medium (6.5)1.0%—May 11, 2022
There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
CVE-2022-27046High (8.8)1.0%—Apr 8, 2022
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
CVE-2022-27044High (8.8)1.0%—Apr 8, 2022
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
CVE-2022-27938Medium (5.5)0.61%—Mar 26, 2022
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
CVE-2021-46700Medium (6.5)0.82%—Feb 19, 2022
In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.
CVE-2020-21548High (8.8)1.1%—Sep 17, 2021
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
CVE-2020-21547High (8.8)1.1%—Sep 17, 2021
Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
CVE-2020-21050Medium (6.5)1.6%—Sep 14, 2021
Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
CVE-2020-21049Medium (6.5)1.4%—Sep 14, 2021
An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
CVE-2020-21048Medium (6.5)1.4%—Sep 14, 2021
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
CVE-2020-21677Medium (6.5)0.90%—Aug 10, 2021
A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.
CVE-2020-36120High (7.5)1.2%—Apr 14, 2021
Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS).
CVE-2020-19668Medium (6.5)0.86%—Nov 20, 2020
Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.
CVE-2020-11721Medium (6.5)0.94%—Apr 12, 2020
load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.
CVE-2019-20205High (8.8)1.0%—Jan 2, 2020
libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
CVE-2019-20140High (8.8)1.1%—Dec 30, 2019
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.
CVE-2019-20094High (8.8)1.0%—Dec 30, 2019
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c.
CVE-2019-20024Medium (6.5)0.99%—Dec 27, 2019
A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
CVE-2019-20023Medium (6.5)0.99%—Dec 27, 2019
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.