← Back

Libsixel

libsixel

Vendor: Libsixel Project • 43 CVEs

CVEs (43)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Feb 23, 2026
N/A· v4
4.0 MEDIUM· v3
N/A· v2
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Aug 21, 2025
1.9 LOW· v4
7.8 HIGH· v3
4.3 MEDIUM· v2
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based b...Show more
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is identified as 316c086e79d66b62c0c4bc66229ee894e4fdb7d1. Applying a patch is advised to resolve this issue.Show less
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
May 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
May 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
2Libsixel
Libsixel Project
2Libsixel
Libsixel
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
2Libsixel
Libsixel Project
2Libsixel
Libsixel
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
3Libsixel
Libsixel ProjectSaitoha
3Libsixel
LibsixelLibsixel
Jun 17, 2026
Mar 26, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Feb 19, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.
2Libsixel
Libsixel Project
2Libsixel
Libsixel
Jun 17, 2026
Jan 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Sep 17, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Sep 17, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Sep 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Sep 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Sep 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Aug 10, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Apr 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS).
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Nov 20, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Apr 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.