libsixel_project CVE Vulnerabilities & Metrics

Focus on libsixel_project vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About libsixel_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with libsixel_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total libsixel_project CVEs: 41
Earliest CVE date: 15 Jul 2018, 18:29 UTC
Latest CVE date: 11 May 2022, 14:15 UTC

Latest CVE reference: CVE-2022-29978

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical libsixel_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.46

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 37
7.0-8.9 4
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS libsixel_project CVEs

These are the five CVEs with the highest CVSS scores for libsixel_project, sorted by severity first and recency.

All CVEs for libsixel_project

CVE-2022-29978 libsixel_project vulnerability CVSS: 4.3 11 May 2022, 14:15 UTC

There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.

CVE-2022-29977 libsixel_project vulnerability CVSS: 4.3 11 May 2022, 14:15 UTC

There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.

CVE-2021-40656 libsixel_project vulnerability CVSS: 6.8 08 Apr 2022, 16:15 UTC

libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.

CVE-2022-27046 libsixel_project vulnerability CVSS: 6.8 08 Apr 2022, 15:15 UTC

libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.

CVE-2022-27044 libsixel_project vulnerability CVSS: 6.8 08 Apr 2022, 15:15 UTC

libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.

CVE-2021-41715 libsixel_project vulnerability CVSS: 6.8 08 Apr 2022, 15:15 UTC

libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.

CVE-2022-27938 libsixel_project vulnerability CVSS: 4.3 26 Mar 2022, 13:15 UTC

stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.

CVE-2021-46700 libsixel_project vulnerability CVSS: 4.3 19 Feb 2022, 19:15 UTC

In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.

CVE-2021-45340 libsixel_project vulnerability CVSS: 4.3 25 Jan 2022, 12:15 UTC

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

CVE-2020-21548 libsixel_project vulnerability CVSS: 6.8 17 Sep 2021, 21:15 UTC

Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.

CVE-2020-21547 libsixel_project vulnerability CVSS: 6.8 17 Sep 2021, 21:15 UTC

Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.

CVE-2020-21050 libsixel_project vulnerability CVSS: 4.3 14 Sep 2021, 16:15 UTC

Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.

CVE-2020-21049 libsixel_project vulnerability CVSS: 4.3 14 Sep 2021, 16:15 UTC

An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.

CVE-2020-21048 libsixel_project vulnerability CVSS: 4.3 14 Sep 2021, 16:15 UTC

An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.

CVE-2020-21677 libsixel_project vulnerability CVSS: 4.3 10 Aug 2021, 21:15 UTC

A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.

CVE-2020-36120 libsixel_project vulnerability CVSS: 5.0 14 Apr 2021, 14:15 UTC

Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS).

CVE-2020-19668 libsixel_project vulnerability CVSS: 4.3 20 Nov 2020, 16:15 UTC

Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.

CVE-2020-11721 libsixel_project vulnerability CVSS: 4.3 12 Apr 2020, 19:15 UTC

load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.

CVE-2019-20205 libsixel_project vulnerability CVSS: 6.8 02 Jan 2020, 14:16 UTC

libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.

CVE-2019-20140 libsixel_project vulnerability CVSS: 6.8 30 Dec 2019, 17:15 UTC

An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.

CVE-2019-20094 libsixel_project vulnerability CVSS: 6.8 30 Dec 2019, 04:15 UTC

An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c.

CVE-2019-20024 libsixel_project vulnerability CVSS: 4.3 27 Dec 2019, 02:15 UTC

A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.

CVE-2019-20023 libsixel_project vulnerability CVSS: 4.3 27 Dec 2019, 02:15 UTC

A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.

CVE-2019-20022 libsixel_project vulnerability CVSS: 4.3 27 Dec 2019, 02:15 UTC

An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.

CVE-2019-19778 libsixel_project vulnerability CVSS: 6.8 13 Dec 2019, 02:15 UTC

An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.

CVE-2019-19777 libsixel_project vulnerability CVSS: 6.8 13 Dec 2019, 02:15 UTC

stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.

CVE-2019-19638 libsixel_project vulnerability CVSS: 7.5 08 Dec 2019, 03:15 UTC

An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an integer overflow.

CVE-2019-19637 libsixel_project vulnerability CVSS: 7.5 08 Dec 2019, 03:15 UTC

An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.

CVE-2019-19636 libsixel_project vulnerability CVSS: 7.5 08 Dec 2019, 03:15 UTC

An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.

CVE-2019-19635 libsixel_project vulnerability CVSS: 7.5 08 Dec 2019, 03:15 UTC

An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.

CVE-2019-11024 libsixel_project vulnerability CVSS: 4.3 08 Apr 2019, 23:29 UTC

The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.

CVE-2019-3574 libsixel_project vulnerability CVSS: 6.8 02 Jan 2019, 15:29 UTC

In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.

CVE-2019-3573 libsixel_project vulnerability CVSS: 4.3 02 Jan 2019, 15:29 UTC

In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.

CVE-2018-19763 libsixel_project vulnerability CVSS: 4.3 30 Nov 2018, 03:29 UTC

There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a denial of service.

CVE-2018-19762 libsixel_project vulnerability CVSS: 6.8 30 Nov 2018, 03:29 UTC

There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a denial of service or possibly unspecified other impact.

CVE-2018-19761 libsixel_project vulnerability CVSS: 4.3 30 Nov 2018, 03:29 UTC

There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of service.

CVE-2018-19759 libsixel_project vulnerability CVSS: 4.3 30 Nov 2018, 03:29 UTC

There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.

CVE-2018-19757 libsixel_project vulnerability CVSS: 4.3 30 Nov 2018, 03:29 UTC

There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.

CVE-2018-19756 libsixel_project vulnerability CVSS: 4.3 30 Nov 2018, 03:29 UTC

There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of service.

CVE-2018-14073 libsixel_project vulnerability CVSS: 5.0 15 Jul 2018, 18:29 UTC

libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c.

CVE-2018-14072 libsixel_project vulnerability CVSS: 5.0 15 Jul 2018, 18:29 UTC

libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, image_buffer_resize in fromsixel.c, and sixel_decode_raw in fromsixel.c.