VendorsNothingsstb_image.hall versions
Vulnerabilities

Nothings Stb Image.h

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2023-45666
Possible double-free or memory leak in stbi__load_gif_main in stb_image
Published 2023-10-20 · Modified
9.8EPSS 0.010
CVE-2022-28042
stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
Published 2022-04-15 · Modified
8.8EPSS 0.016
CVE-2018-16981
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
Published 2018-09-12 · Modified
8.8EPSS 0.016
CVE-2019-19777
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
Published 2019-12-13 · Modified
8.8EPSS 0.014
CVE-2023-45664
Double-free in stbi__load_gif_main_outofmem in stb_image
Published 2023-10-20 · Modified
8.8EPSS 0.009
CVE-2025-3409
Nothings stb stb_include_string stack-based overflow
Published 2025-04-08 · Analyzed
8.8EPSS 0.005
CVE-2025-3408
Nothings stb stb_dupreplace integer overflow
Published 2025-04-08 · Analyzed
8.8EPSS 0.005
CVE-2025-3407
Nothings stb stbhw_build_tileset_from_image out-of-bounds
Published 2025-04-08 · Analyzed
8.8EPSS 0.005
CVE-2023-45662
Multi-byte read heap buffer overflow in stbi__vertical_flip in stb_image
Published 2023-10-20 · Modified
8.1EPSS 0.007
CVE-2023-45667
Null pointer dereference because of an uninitialized variable in stb_image
Published 2023-10-20 · Modified
7.5EPSS 0.011
CVE-2021-42716
An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location.
Published 2021-10-21 · Modified
7.1EPSS 0.015
CVE-2023-45661
Wild address read in stbi__gif_load_next in stb_image
Published 2023-10-20 · Modified
7.1EPSS 0.006
CVE-2022-28041
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Published 2022-04-15 · Modified
6.5EPSS 0.021
CVE-2023-43281
Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a crafted file to the stbi_load_gif_main function.
Published 2023-10-24 · Modified
6.5EPSS 0.010
CVE-2019-20056
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.
Published 2019-12-29 · Modified
6.5EPSS 0.009
CVE-2025-3406
Nothings stb Header Array stbhw_build_tileset_from_image out-of-bounds
Published 2025-04-08 · Analyzed
6.5EPSS 0.006
CVE-2021-42715
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.
Published 2021-10-21 · Modified
5.5EPSS 0.013
CVE-2023-45663
Disclosure of uninitialized memory in stbi__tga_load in stb_image
Published 2023-10-20 · Modified
5.5EPSS 0.007
CVE-2023-43898
Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted pic file.
Published 2023-10-03 · Modified
5.5EPSS 0.003