Known Vulnerabilities for products from Enlightenment

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Enlightenment".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-37706 json enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the sys... 7.8 - HIGH 2022-12-25 2023-01-04
CVE-2020-12761 json modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bo... 9.1 - CRITICAL 2020-05-09 2021-07-21
CVE-2018-20167 json Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat READM... 7.8 - HIGH 2018-12-17 2019-10-03
CVE-2016-4024 json Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimen... 9.8 - CRITICAL 2016-05-13 2018-10-30
CVE-2016-3994 json The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sens... 8.2 - HIGH 2016-05-13 2016-12-01
CVE-2016-3993 json Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause... 7.5 - HIGH 2016-05-13 2016-12-01
CVE-2015-8971 json Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and... 7.8 - HIGH 2017-01-23 2020-02-24
CVE-2014-9771 json Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denial of service (memory consumption or applicati... 7.5 - HIGH 2016-05-13 2016-12-01
CVE-2014-9764 json imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file. 7.5 - HIGH 2016-05-13 2017-07-01
CVE-2014-9763 json imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a c... 7.5 - HIGH 2016-05-13 2017-07-01
CVE-2014-9762 json imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a color... 7.5 - HIGH 2016-05-13 2017-07-01
CVE-2014-1846 json Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method. 7.8 - HIGH 2018-04-27 2018-06-07
CVE-2014-1845 json An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure ... 7.8 - HIGH 2018-04-27 2018-06-07
CVE-2011-5326 json imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by draw... 7.5 - HIGH 2016-05-13 2016-12-01
CVE-2010-0991 json Multiple heap-based buffer overflows in imlib2 1.4.3 allow context-dependent attackers to execute arbitrary code via a crafte... 6.8 - MEDIUM 2010-04-22 2018-10-10
CVE-2008-6079 json imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPE... Not Provided 2009-02-06 2026-04-23
CVE-2008-5187 json The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of serv... Not Provided 2008-11-21 2026-04-23
CVE-2006-4809 json Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote ... Not Provided 2006-11-07 2026-04-23
CVE-2006-4808 json Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote a... Not Provided 2006-11-07 2026-04-23
CVE-2006-4807 json loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of ... Not Provided 2006-11-07 2026-04-23

Known software with vulnerabilities from Enlightenment

Type Vendor Product Version
ApplicationEnlightenmentEnlightenment0.17.0
ApplicationEnlightenmentImlib21.2.1
ApplicationEnlightenmentTerminology0.1.0