VendorsMiniUPnP Projectngifliball versions
Vulnerabilities

MiniUPnP Project ngiflib

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2018-11575
ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg.
Published 2018-05-31 · Modified
9.8EPSS 0.015
CVE-2018-11576
ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor.
Published 2018-05-31 · Modified
9.8EPSS 0.014
CVE-2018-10717
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file, a different vulnerability than CVE-2018-10677.
Published 2018-05-03 · Modified
8.8EPSS 0.020
CVE-2019-16346
ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.
Published 2019-09-16 · Modified
8.8EPSS 0.016
CVE-2019-16347
ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.
Published 2019-09-16 · Modified
8.8EPSS 0.015
CVE-2018-10677
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.
Published 2018-05-02 · Modified
8.8EPSS 0.015
CVE-2019-20219
ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c.
Published 2020-01-02 · Modified
8.8EPSS 0.013
CVE-2021-36531
ngiflib 0.4 has a heap overflow in GetByte() at ngiflib.c:70 in NGIFLIB_NO_FILE mode, GetByte() reads memory buffer without checking the boundary.
Published 2021-08-27 · Modified
8.8EPSS 0.011
CVE-2021-36530
ngiflib 0.4 has a heap overflow in GetByteStr() at ngiflib.c:108 in NGIFLIB_NO_FILE mode, GetByteStr() copy memory buffer without checking the boundary.
Published 2021-08-27 · Modified
8.8EPSS 0.011
CVE-2019-19011
MiniUPnP ngiflib 0.4 has a NULL pointer dereference in GifIndexToTrueColor in ngiflib.c via a file that lacks a palette.
Published 2019-11-16 · Modified
7.5EPSS 0.017
CVE-2018-11657
ngiflib.c in MiniUPnP ngiflib 0.4 has an infinite loop in DecodeGifImg and LoadGif.
Published 2018-06-01 · Modified
7.5EPSS 0.011
CVE-2018-11578
GifIndexToTrueColor in ngiflib.c in MiniUPnP ngiflib 0.4 has a Segmentation fault.
Published 2018-05-31 · Modified
6.5EPSS 0.010
CVE-2022-30858
An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0
Published 2023-07-17 · Modified
6.5EPSS 0.006
CVE-2020-24221
An issue was discovered in GetByte function in miniupnp ngiflib version 0.4, allows local attackers to cause a denial of service (DoS) via crafted .gif file (infinite loop).
Published 2023-08-11 · Modified
5.5EPSS 0.003
CVE-2023-37748
ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c.
Published 2023-07-19 · Modified
5.5EPSS 0.003
CVE-2023-39114
ngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibSDL.c. This vulnerability is triggered when running the program SDLaffgif.
Published 2023-08-02 · Modified
5.5EPSS 0.003
CVE-2023-39113
ngiflib commit fb271 was discovered to contain a segmentation violation via the function "main" at gif2tag.c. This vulnerability is triggered when running the program gif2tga.
Published 2023-08-02 · Modified
5.5EPSS 0.003