Known Vulnerabilities for products from Cimg

Listed below are 13 of the newest known vulnerabilities associated with the vendor "Cimg".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-47667 json Not Provided 2026-07-21 2026-07-21
CVE-2026-42146 json Not Provided 2026-05-04 2026-05-06
CVE-2026-42144 json Not Provided 2026-05-04 2026-05-05
CVE-2023-41484 json An issue in cimg.eu Cimg Library v2.9.3 allows an attacker to obtain sensitive information via a crafted JPEG file. 8.1 - HIGH 2023-09-20 2023-09-22
CVE-2022-1325 json A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header fie... 5.5 - MEDIUM 2022-08-31 2022-09-07
CVE-2020-25693 json A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be ... 8.1 - HIGH 2020-12-03 2023-11-07
CVE-2019-1010174 json CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_netwo... 9.8 - CRITICAL 2019-07-25 2023-03-01
CVE-2019-13568 json CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a malfo... 8.8 - HIGH 2019-07-31 2020-08-24
CVE-2018-7641 json An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp ... 7.8 - HIGH 2018-03-02 2020-11-02
CVE-2018-7640 json An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp ... 7.8 - HIGH 2018-03-02 2020-11-02
CVE-2018-7639 json An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp ... 7.8 - HIGH 2018-03-02 2020-11-02
CVE-2018-7638 json An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp ... 7.8 - HIGH 2018-03-02 2020-11-02
CVE-2018-7637 json An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp ... 7.8 - HIGH 2018-03-02 2020-11-02
CVE-2018-7589 json An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image. 7.8 - HIGH 2018-03-01 2020-11-02
CVE-2018-7588 json An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp ... 7.8 - HIGH 2018-03-01 2020-11-02
CVE-2018-7587 json An issue was discovered in CImg v.220. DoS occurs when loading a crafted bmp image that triggers an allocation failure in loa... 7.8 - HIGH 2018-03-01 2019-06-26

Known software with vulnerabilities from Cimg

Type Vendor Product Version
ApplicationCimgCimg-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report