Home/Product/giflib project giflib
Product

giflib project giflib

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-26740
all versions
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension o
8.2HIGH
CVE-2026-23868
>= 5.0.0 and <= 6.1.1
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling
5.1MEDIUM
CVE-2024-45993
all versions
Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.
6.5MEDIUM
CVE-2023-48161
all versions
Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the Dum
7.1HIGH
CVE-2023-39742
all versions
giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.
5.5MEDIUM
CVE-2021-40633
all versions
A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory except
8.8HIGH
CVE-2022-28506
all versions
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
5.5MEDIUM
CVE-2020-23922
<= 5.1.4
An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.
7.1HIGH
CVE-2019-15133
< 5.1.7
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_li
6.5MEDIUM
CVE-2018-11490
>= 3.0 and <= 3.1.1
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has
8.8HIGH
CVE-2018-11489
>= 3.0 and <= 3.1.1
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has
8.8HIGH
CVE-2016-3177
all versions
Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.
9.8CRITICAL
CVE-2016-3977
<= 5.1.2
Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (appl
5.5MEDIUM
CVE-2015-7555
<= 5.1.1
Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via
5.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin