Libbpg Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 10
    Known Exploited: 0
    0
    Critical Level Threats
    9
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2017-2575

    A vulnerability was found while fuzzing libbpg 0.9.7. It is a NULL pointer dereference issue due to missing check of the return value of function malloc in the BPG encoder. This vulnerability appeared while converting a malicious JPEG file to BPG.

    Last Modified: Nov 21, 2024
    Published: Aug 22, 2018

    CVE-2018-12447

    The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integer overflow that leads to a heap-based buffer overflow and remote code execution.

    Last Modified: Nov 21, 2024
    Published: Jun 15, 2018

    CVE-2017-13136

    The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.

    Last Modified: Apr 20, 2025
    Published: Nov 16, 2017

    CVE-2017-14034

    The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.7 and other products, miscalculates a memcpy destination address, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact.

    Last Modified: Apr 20, 2025
    Published: Nov 16, 2017

    CVE-2017-13135

    A NULL Pointer Dereference exists in VideoLAN x265, as used in libbpg 0.9.7 and other products, because the CUData::initialize function in common/cudata.cpp mishandles memory-allocation failure.

    Last Modified: Apr 20, 2025
    Published: Nov 16, 2017
    Items Per Page
    Libbpg_Project Vulnerabilities & Security CVEs | CVE-DB