← Back

Pixman

pixman

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Pixman
pixman

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pixman
1Pixman
Nov 21, 2024
Jul 17, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.
3Debian
FedoraprojectPixman
3Debian Linux
FedoraPixman
May 2, 2025
Nov 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.
1Pixman
1Pixman
Nov 21, 2024
Jul 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially,...Show more
An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.Show less
2Canonical
Pixman
2Pixman
Ubuntu Linux
May 6, 2026
Apr 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and...Show more
Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and stride values.Show less
5Canonical
DebianOpensuse+2 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+7 more
Apr 29, 2026
Jan 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom...Show more
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.Show less
4Canonical
DebianOpensuse+1 more
4Debian Linux
OpensusePixman+1 more
Apr 29, 2026
Jan 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.