An error within the "parsetiffifd()" function (internal/dcrawcommon.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.
An integer overflow error within the "foveonloadcamf()" function (dcrawfoveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a heap-based buffer overflow.
A boundary error within the "foveonloadcamf()" function (dcrawfoveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a stack-based buffer overflow.
A boundary error within the "parsetiffifd()" function (internal/dcrawcommon.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs.