VendorsSaitohalibsixelany version
Vulnerabilities

Saitoha Libsixel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2026-33023
libsixel: Use-after-free in load_with_gdkpixbuf()
Published 2026-04-14 · Analyzed
7.8EPSS 0.003
CVE-2025-9300
saitoha libsixel img2sixel encoder.c sixel_debug_print_palette stack-based overflow
Published 2025-08-21 · Analyzed
7.8EPSS 0.002
CVE-2026-44636
libsixel: integer overflow in encoder
Published 2026-05-14 · Modified
7.8EPSS 0.001
CVE-2026-33021
libsixel: Use-after-free in sixel_encoder_encode_bytes()
Published 2026-04-14 · Analyzed
7.3EPSS 0.002
CVE-2026-33020
libsixel: Integer Overflow in write_png_to_file() leads to Heap-based Buffer Overflow
Published 2026-04-14 · Analyzed
7.1EPSS 0.002
CVE-2026-33019
libsixel: Integer overflow leads to Out-of-bounds Read in img2sixel
Published 2026-04-14 · Analyzed
7.1EPSS 0.002
CVE-2026-44637
libsixel: integer overflow in parser
Published 2026-05-14 · Analyzed
7.1EPSS 0.002
CVE-2026-33018
libsixel: Use-After-Free in load_gif()
Published 2026-04-14 · Analyzed
7.0EPSS 0.002
CVE-2020-21050
Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
Published 2021-09-14 · Modified
6.5EPSS 0.016
CVE-2020-21049
An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
Published 2021-09-14 · Analyzed
6.5EPSS 0.014
CVE-2020-21048
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
Published 2021-09-14 · Modified
6.5EPSS 0.014
CVE-2019-20023
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
Published 2019-12-27 · Modified
6.5EPSS 0.010
CVE-2019-20024
A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
Published 2019-12-27 · Modified
6.5EPSS 0.010
CVE-2019-20022
An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
Published 2019-12-27 · Modified
6.5EPSS 0.009
CVE-2022-27938
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
Published 2022-03-26 · Analyzed
5.5EPSS 0.006
CVE-2025-61146
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
Published 2026-02-23 · Analyzed
4.0EPSS 0.001
CVE-2026-44638
libsixel: NULL pointer dereference
Published 2026-05-14 · Analyzed
2.5EPSS 0.001