Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.5) | 0.13% | — | Saitoha Libsixel | 14/5/2026 | 17/6/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointer dereference whenever the allocation fails. The check tests the address of the output parameter (always non-NULL)… | |
| Analizada | Alta (7.1) | 0.17% | — | Saitoha Libsixel | 14/5/2026 | 17/6/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in sixel_decode_raw_impl. context->pos_x grows by repeat_count on every sixel character with no upper bound… | |
| Modificada | Alta (7.8) | 0.14% | — | Saitoha Libsixel | 14/5/2026 | 17/6/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode entry point validates only that width and height are greater than zero, with no… | |
| Analizada | Alta (7.8) | 0.25% | — | Saitoha Libsixel | 14/4/2026 | 25/7/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf() in loader.c. The cleanup path manually frees the sixel_frame_t object and its internal buffers… | |
| Analizada | Alta (7.3) | 0.21% | — | Saitoha Libsixel | 14/4/2026 | 25/7/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the caller-owned pixel buffer pointer directly in frame->pixels without making a defensive copy. When a resize… | |
| Analizada | Alta (7.1) | 0.22% | — | Saitoha Libsixel | 14/4/2026 | 25/7/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1, PAL2, PAL4) are… | |
| Analizada | Alta (7.1) | 0.21% | — | Saitoha Libsixel | 14/4/2026 | 25/7/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds checking. In… | |
| Analizada | Alta (7) | 0.19% | — | Saitoha Libsixel | 14/4/2026 | 25/7/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t object is reused across all frames of an animated GIF and gif_init_frame() unconditionally frees and… | |
| Analizada | Media (4) | 0.12% | — | Saitoha Libsixel | 23/2/2026 | 17/6/2026 | saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c. | |
| Analizada | Baja (1.9) | 0.25% | — | Saitoha Libsixel | 21/8/2025 | 17/6/2026 | A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit has been made… | |
| Modificada | Media (6.5) | 1.0% | — | Saitoha Libsixel | 11/5/2022 | 17/6/2026 | There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file. | |
| Modificada | Media (6.5) | 1.0% | — | Saitoha Libsixel | 11/5/2022 | 17/6/2026 | There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file. | |
| Analizada | Alta (8.8) | 1.0% | — | Libsixel | 8/4/2022 | 17/6/2026 | libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867. | |
| Modificada | Alta (8.8) | 1.0% | — | Saitoha Libsixel | 8/4/2022 | 17/6/2026 | libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388. | |
| Modificada | Alta (8.8) | 1.0% | — | Saitoha Libsixel | 8/4/2022 | 17/6/2026 | libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876. | |
| Analizada | Alta (8.8) | 1.0% | — | Libsixel | 8/4/2022 | 17/6/2026 | libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379. | |
| Analizada | Media (5.5) | 0.61% | — | LibsixelSaitoha Libsixel | 26/3/2022 | 17/6/2026 | stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw. | |
| Modificada | Media (6.5) | 0.82% | — | Saitoha Libsixel | 19/2/2022 | 17/6/2026 | In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free. | |
| Analizada | Media (6.5) | 0.92% | — | Libsixel | 25/1/2022 | 17/6/2026 | In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file. | |
| Modificada | Alta (8.8) | 1.1% | — | Saitoha Libsixel | 17/9/2021 | 17/6/2026 | Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c. | |
| Modificada | Alta (8.8) | 1.1% | — | Saitoha Libsixel | 17/9/2021 | 17/6/2026 | Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c. | |
| Modificada | Media (6.5) | 1.6% | — | Saitoha Libsixel | 14/9/2021 | 17/6/2026 | Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c. | |
| Analizada | Media (6.5) | 1.4% | — | Saitoha Libsixel | 14/9/2021 | 17/6/2026 | An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file. | |
| Modificada | Media (6.5) | 1.4% | — | Saitoha Libsixel | 14/9/2021 | 17/6/2026 | An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file. | |
| Modificada | Media (6.5) | 0.90% | — | Saitoha Libsixel | 10/8/2021 | 17/6/2026 | A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format. |