← Vulnerability feed

Vulnerability record · CVE-2017-14265 · published 11 September 2017

CVE-2017-14265: Libraw memory buffer overflow vulnerability

Libraw · Libraw

A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution attack.

9.8 CVSS 3.0 Critical EPSS 4.3% · top 9.1% CWE-119 · Memory buffer overflow
9.8CVSS 3.0 base score, v2 7.5
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution attack.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/LibRaw/LibRaw/issues/99 PatchThird Party Advisory
https://github.com/LibRaw/LibRaw/issues/99 PatchThird Party Advisory

Track CVE-2017-14265 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24450Libraw integer overflow vulnerabilityAn integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious fi…EPSS 0.57%9.8CVE-2026-20884Libraw integer overflow vulnerabilityAn integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can l…EPSS 0.57%9.8CVE-2026-20889Libraw integer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file …EPSS 0.80%9.8CVE-2026-20911Libraw classic buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially cr…EPSS 0.63%9.8CVE-2026-21413Libraw out-of-bounds write vulnerabilityA heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A speciall…EPSS 0.93%9.8CVE-2025-43964Libraw vulnerabilityIn LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.EPSS 0.41%9.8CVE-2015-8366Libraw vulnerabilityArray index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly exec…EPSS 5.1%9.8CVE-2015-8367Libraw vulnerabilityThe phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2017-14265), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.