See how libsixel project compares to other vendors in security performance
stbimage.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbicreatepngimageraw.
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stbimage.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
An invalid read in the stbimage.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
An invalid memory address dereference was discovered in loadpnm in frompnm.c in libsixel before 1.8.3.
A memory leak was discovered in imagebufferresize in fromsixel.c in libsixel 1.8.4.
A heap-based buffer overflow was discovered in imagebufferresize in fromsixel.c in libsixel before 1.8.4.
libsixel 1.8.1 has a memory leak in sixeldecoderdecode in decoder.c, imagebufferresize in fromsixel.c, and sixeldecoderaw in fromsixel.c.
Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gifprocessraster at fromgif.c.
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
A heap-based buffer overflow in the sixelencoderoutputwithoutmacro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.
There is a NULL pointer dereference at function sixelhelpersetadditionalmessage (status.c) in libsixel 1.8.2 that will cause a denial of service.
There is an illegal address access at fromsixel.c (function: sixeldecoderawimpl) in libsixel 1.8.2 that will cause a denial of service.
libsixel 1.8.4 has an integer overflow in sixelframeresize in frame.c.
libsixel 1.8.1 has a memory leak in sixelallocatornew in allocator.c.
Unverified indexs into the array lead to out of bound access in the gifoutcode function in fromgif.c in libsixel 1.8.6.
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gifoutcode at fromgif.c.
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gifinitframe at fromgif.c.
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function loadsixel at loader.c.
stbimage.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbiloadmain.
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixeldecoderawimpl at fromsixel.c.
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixeldecoderawimpl at fromsixel.c.
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixelencodebody at tosixel.c.
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function loadpnm at frompnm.c, due to an integer overflow.
In libsixel 1.8.6, sixelencoderoutputwithoutmacro (called from sixelencoderencodeframe in encoder.c) has a double free.
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixelencodehighcolor function in tosixel.c.
Libsixel 1.8.2 contains a heap-based buffer overflow in the ditherfuncfs function in tosixel.c.
Buffer Overflow in the "sixelencoderencodebytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS).
loadpng in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.
The loadpnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.