Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

51 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.5)0.13%—Saitoha Libsixel14/5/202617/6/2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointer dereference whenever the allocation fails. The check tests the address of the output parameter (always non-NULL)…
AnalizadaAlta (7.1)0.17%—Saitoha Libsixel14/5/202617/6/2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in sixel_decode_raw_impl. context->pos_x grows by repeat_count on every sixel character with no upper bound…
ModificadaAlta (7.8)0.14%—Saitoha Libsixel14/5/202617/6/2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode entry point validates only that width and height are greater than zero, with no…
AnalizadaAlta (7.8)0.25%—Saitoha Libsixel14/4/202625/7/2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf() in loader.c. The cleanup path manually frees the sixel_frame_t object and its internal buffers…
AnalizadaAlta (7.3)0.21%—Saitoha Libsixel14/4/202625/7/2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the caller-owned pixel buffer pointer directly in frame->pixels without making a defensive copy. When a resize…
AnalizadaAlta (7.1)0.22%—Saitoha Libsixel14/4/202625/7/2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1, PAL2, PAL4) are…
AnalizadaAlta (7.1)0.21%—Saitoha Libsixel14/4/202625/7/2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds checking. In…
AnalizadaAlta (7)0.19%—Saitoha Libsixel14/4/202625/7/2026
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t object is reused across all frames of an animated GIF and gif_init_frame() unconditionally frees and…
AnalizadaMedia (4)0.12%—Saitoha Libsixel23/2/202617/6/2026
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
AnalizadaBaja (1.9)0.25%—Saitoha Libsixel21/8/202517/6/2026
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit has been made…
ModificadaMedia (6.5)1.0%—Saitoha Libsixel11/5/202217/6/2026
There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
ModificadaMedia (6.5)1.0%—Saitoha Libsixel11/5/202217/6/2026
There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
AnalizadaAlta (8.8)1.0%—Libsixel8/4/202217/6/2026
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
ModificadaAlta (8.8)1.0%—Saitoha Libsixel8/4/202217/6/2026
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
ModificadaAlta (8.8)1.0%—Saitoha Libsixel8/4/202217/6/2026
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
AnalizadaAlta (8.8)1.0%—Libsixel8/4/202217/6/2026
libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
AnalizadaMedia (5.5)0.61%—LibsixelSaitoha Libsixel26/3/202217/6/2026
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
ModificadaMedia (6.5)0.82%—Saitoha Libsixel19/2/202217/6/2026
In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.
AnalizadaMedia (6.5)0.92%—Libsixel25/1/202217/6/2026
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
ModificadaAlta (8.8)1.1%—Saitoha Libsixel17/9/202117/6/2026
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
ModificadaAlta (8.8)1.1%—Saitoha Libsixel17/9/202117/6/2026
Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
ModificadaMedia (6.5)1.6%—Saitoha Libsixel14/9/202117/6/2026
Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
AnalizadaMedia (6.5)1.4%—Saitoha Libsixel14/9/202117/6/2026
An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
ModificadaMedia (6.5)1.4%—Saitoha Libsixel14/9/202117/6/2026
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
ModificadaMedia (6.5)0.90%—Saitoha Libsixel10/8/202117/6/2026
A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.