Home/Product/saitoha libsixel
Product

saitoha libsixel

51 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-44638
>= 1.0.0 and < 1.8.7-r2
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allo
2.5LOW
CVE-2026-44637
>= 0.11.0 and < 1.8.7-r2
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the
7.1HIGH
CVE-2026-44636
>= 1.4.4 and < 1.8.7-r2
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel
7.4HIGH
CVE-2026-33023
<= 1.8.7
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --
7.8HIGH
CVE-2026-33021
< 1.8.7-r1
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free v
7.3HIGH
CVE-2026-33020
< 1.8.7-r1
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflo
7.1HIGH
CVE-2026-33019
< 1.8.7-r1
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflo
7.1HIGH
CVE-2026-33018
< 1.8.7-r1
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free v
7.0HIGH
CVE-2025-61146
< 1.8.7
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
4.0MEDIUM
CVE-2025-9300
< 1.8.7
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of th
5.3MEDIUM
CVE-2022-29978
all versions
There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers
6.5MEDIUM
CVE-2022-29977
all versions
There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers coul
6.5MEDIUM
CVE-2021-40656
< 1.10.0
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
8.8HIGH
CVE-2022-27046
all versions
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in libsixel/src/dither.c:388.
8.8HIGH
CVE-2022-27044
all versions
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
8.8HIGH
CVE-2021-41715
all versions
libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
8.8HIGH
CVE-2022-27938
< 1.8.7
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png
5.5MEDIUM
CVE-2021-46700
all versions
In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.
6.5MEDIUM
CVE-2021-45340
<= 1.10.3
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers t
6.5MEDIUM
CVE-2020-21548
all versions
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
8.8HIGH
CVE-2020-21547
all versions
Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
8.8HIGH
CVE-2020-21050
< 1.8.3
Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
6.5MEDIUM
CVE-2020-21049
< 1.8.5
An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a
6.5MEDIUM
CVE-2020-21048
< 1.8.4
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted P
6.5MEDIUM
CVE-2020-21677
all versions
A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to
6.5MEDIUM
CVE-2020-36120
all versions
Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS
7.5HIGH
CVE-2020-19668
all versions
Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.
6.5MEDIUM
CVE-2020-11721
all versions
load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can ca
6.5MEDIUM
CVE-2019-20205
all versions
libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
8.8HIGH
CVE-2019-20140
all versions
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.
8.8HIGH
CVE-2019-20094
all versions
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c.
8.8HIGH
CVE-2019-20024
< 1.8.4
A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
6.5MEDIUM
CVE-2019-20023
< 1.8.4
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
6.5MEDIUM
CVE-2019-20022
< 1.8.3
An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
6.5MEDIUM
CVE-2019-19778
all versions
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
8.8HIGH
CVE-2019-19777
all versions
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__lo
8.8HIGH
CVE-2019-19638
all versions
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an
9.8CRITICAL
CVE-2019-19637
all versions
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.
9.8CRITICAL
CVE-2019-19636
all versions
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.
9.8CRITICAL
CVE-2019-19635
all versions
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixe
9.8CRITICAL
CVE-2019-11024
all versions
The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
5.5MEDIUM
CVE-2019-3574
all versions
In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by im
7.8HIGH
CVE-2019-3573
all versions
In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by
5.5MEDIUM
CVE-2018-19763
all versions
There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a denial of ser
5.5MEDIUM
CVE-2018-19762
all versions
There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a denial of
7.8HIGH
CVE-2018-19761
all versions
There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of
5.5MEDIUM
CVE-2018-19759
all versions
There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a
5.5MEDIUM
CVE-2018-19757
all versions
There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a
6.5MEDIUM
CVE-2018-19756
all versions
There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of ser
5.5MEDIUM
CVE-2018-14073
all versions
libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c.
7.5HIGH
CVE-2018-14072
all versions
libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, image_buffer_resize in fromsixel.c, and sixel_decode_raw in
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin