Search CVE reports


Toggle filters

1 – 10 of 60 results


CVE-2025-43964

Medium priority

Some fixes available 7 of 57

In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

8 affected packages

dcraw, ufraw, darktable, exactimage, rawtherapee...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Fixed
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2025-43963

Medium priority

Some fixes available 7 of 57

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.

8 affected packages

ufraw, darktable, exactimage, dcraw, rawtherapee...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Fixed
Show all 8 packages Show less packages

CVE-2025-43962

Medium priority

Some fixes available 7 of 57

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.

8 affected packages

ufraw, darktable, exactimage, dcraw, rawtherapee...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Fixed
Show all 8 packages Show less packages

CVE-2025-43961

Medium priority

Some fixes available 7 of 57

In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.

8 affected packages

dcraw, ufraw, darktable, exactimage, libraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Fixed
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2020-22628

Medium priority

Some fixes available 2 of 58

Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.

9 affected packages

xbmc, libraw, ufraw, darktable, exactimage...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xbmc Not in release Not in release Not in release Not in release
libraw Not affected Not affected Fixed Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Not affected Not affected Fixed Not affected
Show all 9 packages Show less packages

CVE-2023-1729

Medium priority

Some fixes available 12 of 74

A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.

9 affected packages

ufraw, xbmc, darktable, exactimage, libraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ufraw Not in release Not in release Not in release Needs evaluation
xbmc Not in release Not in release Not in release Not in release
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Not affected Fixed Fixed Fixed
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 9 packages Show less packages

CVE-2021-45985

Medium priority
Needs evaluation

In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.

9 affected packages

lua5.2, lua5.3, lua5.4, lua50, memcached...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lua5.2 Not affected Not affected Not affected Not affected
lua5.3 Not affected Not affected Not affected Not affected
lua5.4 Not affected Not affected Not in release Not in release
lua50 Not in release Not in release Not affected Not affected
memcached Not affected Not affected Not affected Not affected
tup Needs evaluation Needs evaluation Needs evaluation Not in release
vifm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lua5.1 Not affected Not affected Not affected Not affected
Show all 9 packages Show less packages

CVE-2021-32142

Low priority

Some fixes available 10 of 72

Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Not affected Not affected Fixed Not affected
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Fixed Fixed Fixed Vulnerable
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ufraw Not in release Not in release Needs evaluation
xbmc Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2020-35535

Medium priority
Needs evaluation

In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when processing srf files.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Not affected Not affected Not affected Not affected
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xbmc Not in release Not in release Not in release Not in release
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Needs evaluation
Show all 9 packages Show less packages

CVE-2020-35534

Medium priority
Needs evaluation

In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Not affected Not affected Not affected Not affected
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xbmc Not in release Not in release Not in release Not in release
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Needs evaluation
Show all 9 packages Show less packages