See how libsixel project compares to other vendors in security performance
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component mallocstub.c.
There is a floating point exception error in sixelencoderdoresize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
There is an assertion failure error in stbijpeghuffdecode, stbimage.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
stbimage.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbicreatepngimageraw.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
In libsixel 1.8.6, sixelencoderoutputwithoutmacro (called from sixelencoderencodeframe in encoder.c) has a double free.
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stbimage.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixelencodehighcolor function in tosixel.c.
Libsixel 1.8.2 contains a heap-based buffer overflow in the ditherfuncfs function in tosixel.c.
Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gifprocessraster at fromgif.c.
An invalid read in the stbimage.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
A heap-based buffer overflow in the sixelencoderoutputwithoutmacro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.
Buffer Overflow in the "sixelencoderencodebytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS).
Unverified indexs into the array lead to out of bound access in the gifoutcode function in fromgif.c in libsixel 1.8.6.
loadpng in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.
libsixel 1.8.4 has an integer overflow in sixelframeresize in frame.c.
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gifoutcode at fromgif.c.
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gifinitframe at fromgif.c.
An invalid memory address dereference was discovered in loadpnm in frompnm.c in libsixel before 1.8.3.
A heap-based buffer overflow was discovered in imagebufferresize in fromsixel.c in libsixel before 1.8.4.
A memory leak was discovered in imagebufferresize in fromsixel.c in libsixel 1.8.4.
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function loadsixel at loader.c.
stbimage.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbiloadmain.
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixelencodebody at tosixel.c.
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixeldecoderawimpl at fromsixel.c.