enlightenment CVE Vulnerabilities & Metrics

Focus on enlightenment vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About enlightenment Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with enlightenment. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total enlightenment CVEs: 17
Earliest CVE date: 25 Mar 2002, 05:00 UTC
Latest CVE date: 09 Feb 2024, 15:15 UTC

Latest CVE reference: CVE-2024-25450

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical enlightenment CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.32

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 17
7.0-8.9 6
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS enlightenment CVEs

These are the five CVEs with the highest CVSS scores for enlightenment, sorted by severity first and recency.

All CVEs for enlightenment

CVE-2024-25450 enlightenment vulnerability CVSS: 0 09 Feb 2024, 15:15 UTC

imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().

CVE-2024-25448 enlightenment vulnerability CVSS: 0 09 Feb 2024, 15:15 UTC

An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

CVE-2024-25447 enlightenment vulnerability CVSS: 0 09 Feb 2024, 15:15 UTC

An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

CVE-2022-37706 enlightenment vulnerability CVSS: 0 25 Dec 2022, 19:15 UTC

enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.

CVE-2020-12761 enlightenment vulnerability CVSS: 6.4 09 May 2020, 18:15 UTC

modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.

CVE-2018-20167 enlightenment vulnerability CVSS: 6.8 17 Dec 2018, 05:29 UTC

Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn is used. A popmedia control sequence can allow the malicious execution of executable file formats registered in the X desktop share MIME types (/usr/share/applications). The control sequence defers unknown file types to the handle_unknown_media() function, which executes xdg-open against the filename specified in the sequence. The use of xdg-open for all unknown file types allows executable file formats with a registered shared MIME type to be executed. An attacker can achieve remote code execution by introducing an executable file and a plain text file containing the control sequence through a fake software project (e.g., in Git or a tarball). When the control sequence is rendered (such as with cat), the executable file will be run.

CVE-2014-1846 enlightenment vulnerability CVSS: 4.6 27 Apr 2018, 16:29 UTC

Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.

CVE-2014-1845 enlightenment vulnerability CVSS: 4.6 27 Apr 2018, 16:29 UTC

An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the environment.

CVE-2015-8971 enlightenment vulnerability CVSS: 4.6 23 Jan 2017, 21:59 UTC

Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063.

CVE-2016-4024 enlightenment vulnerability CVSS: 7.5 13 May 2016, 16:59 UTC

Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.

CVE-2016-3994 enlightenment vulnerability CVSS: 6.4 13 May 2016, 16:59 UTC

The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers an out-of-bounds read.

CVE-2016-3993 enlightenment vulnerability CVSS: 5.0 13 May 2016, 16:59 UTC

Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted coordinates.

CVE-2014-9771 enlightenment vulnerability CVSS: 5.0 13 May 2016, 16:59 UTC

Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted image, which triggers an invalid read operation.

CVE-2014-9764 enlightenment vulnerability CVSS: 5.0 13 May 2016, 16:59 UTC

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file.

CVE-2014-9763 enlightenment vulnerability CVSS: 5.0 13 May 2016, 16:59 UTC

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.

CVE-2014-9762 enlightenment vulnerability CVSS: 5.0 13 May 2016, 16:59 UTC

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a colormap.

CVE-2011-5326 enlightenment vulnerability CVSS: 5.0 13 May 2016, 16:59 UTC

imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.

CVE-2010-0991 enlightenment vulnerability CVSS: 6.8 22 Apr 2010, 14:30 UTC

Multiple heap-based buffer overflows in imlib2 1.4.3 allow context-dependent attackers to execute arbitrary code via a crafted (1) ARGB, (2) XPM, or (3) BMP file, related to the IMAGE_DIMENSIONS_OK macro in lib/image.h.

CVE-2008-6079 enlightenment vulnerability CVSS: 10.0 06 Feb 2009, 11:30 UTC

imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related to "several heap and stack based buffer overflows - partly due to integer overflows."

CVE-2008-5187 enlightenment vulnerability CVSS: 7.5 21 Nov 2008, 02:30 UTC

The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.

CVE-2006-4806 enlightenment vulnerability CVSS: 5.1 07 Nov 2006, 00:07 UTC

Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.

CVE-2006-4809 enlightenment vulnerability CVSS: 5.1 07 Nov 2006, 00:07 UTC

Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM image.

CVE-2006-4807 enlightenment vulnerability CVSS: 2.6 07 Nov 2006, 00:07 UTC

loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted TGA image that triggers an out-of-bounds memory read, a different issue than CVE-2006-4808.

CVE-2006-4808 enlightenment vulnerability CVSS: 2.6 07 Nov 2006, 00:07 UTC

Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image.

CVE-2004-1025 enlightenment vulnerability CVSS: 10.0 10 Jan 2005, 05:00 UTC

Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.

CVE-2004-1026 enlightenment vulnerability CVSS: 10.0 10 Jan 2005, 05:00 UTC

Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.

CVE-2004-0817 enlightenment vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.

CVE-2004-0802 enlightenment vulnerability CVSS: 5.1 31 Dec 2004, 05:00 UTC

Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.

CVE-2004-0827 enlightenment vulnerability CVSS: 7.5 16 Sep 2004, 04:00 UTC

Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.

CVE-2002-0167 enlightenment vulnerability CVSS: 7.5 22 Apr 2002, 04:00 UTC

Imlib before 1.9.13 sometimes uses the NetPBM package to load trusted images, which could allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain weaknesses of NetPBM.

CVE-2002-0168 enlightenment vulnerability CVSS: 7.5 22 Apr 2002, 04:00 UTC

Vulnerability in Imlib before 1.9.13 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by manipulating arguments that are passed to malloc, which results in a heap corruption.

CVE-2002-0143 enlightenment vulnerability CVSS: 4.6 25 Mar 2002, 05:00 UTC

Buffer overflow in Eterm of Enlightenment Imlib2 1.0.4 and earlier allows local users to execute arbitrary code via a long HOME environment variable.