giflib_project CVE Vulnerabilities & CVE List (14)

Products (CPE): — CVEs: 14

giflib_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all giflib_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk memory corruption and vendor risk buffer overflow and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 114 of 14 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-26740 Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size. [email protected] 8.2 0.15% 2026-03-18 2026-03-21
CVE-2026-23868 Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible. [email protected] 5.1 0.02% 2026-03-10 2026-05-07
CVE-2024-45993 Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb. [email protected] 6.5 0.15% 2024-09-30 2025-07-10
CVE-2023-48161 Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c [email protected] 7.1 0.05% 2023-11-22 2024-11-21
CVE-2023-39742 giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c. [email protected] 5.5 0.02% 2023-08-25 2024-11-21
CVE-2021-40633 A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file. [email protected] 8.8 0.81% 2022-06-14 2024-11-21
CVE-2022-28506 There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45. [email protected] 5.5 0.07% 2022-04-25 2024-11-21
CVE-2020-23922 An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read. [email protected] 7.1 2.12% 2021-04-21 2024-11-21
CVE-2019-15133 In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero. [email protected] 6.5 1.30% 2019-08-17 2024-11-21
CVE-2018-11490 The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact. [email protected] 8.8 0.22% 2018-05-26 2024-11-21
CVE-2018-11489 The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact. [email protected] 8.8 0.53% 2018-05-26 2024-11-21
CVE-2016-3177 Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors. [email protected] 9.8 0.46% 2017-01-23 2026-05-13
CVE-2016-3977 Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file. [email protected] 5.5 0.73% 2016-04-21 2026-05-06
CVE-2015-7555 Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via crafted image and logical screen width fields in a GIF file. [email protected] 5.5 0.30% 2016-04-13 2026-05-06
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence