← Vulnerability feed

Vulnerability record · CVE-2015-8367 · published 14 January 2020

CVE-2015-8367: Libraw vulnerability

Libraw · Libraw

The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.

9.8 CVSS 3.1 Critical EPSS 5.6% · top 7.4% CWE-665 · CWE-665
9.8CVSS 3.1 base score, v2 7.5
5.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-8367 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24450Libraw integer overflow vulnerabilityAn integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious fi…EPSS 0.57%9.8CVE-2026-20884Libraw integer overflow vulnerabilityAn integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can l…EPSS 0.57%9.8CVE-2026-20889Libraw integer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file …EPSS 0.80%9.8CVE-2026-20911Libraw classic buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially cr…EPSS 0.63%9.8CVE-2026-21413Libraw out-of-bounds write vulnerabilityA heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A speciall…EPSS 0.93%9.8CVE-2025-43964Libraw vulnerabilityIn LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.EPSS 0.41%9.8CVE-2015-8366Libraw vulnerabilityArray index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly exec…EPSS 5.1%9.8CVE-2017-14265Libraw memory buffer overflow vulnerabilityA Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote deni…EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2015-8367), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.