← Vulnerability feed

Vulnerability record · CVE-2018-19655 · published 29 November 2018

CVE-2018-19655: Dcraw project dcraw out-of-bounds write vulnerability

Dcraw Project · Dcraw

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

8.8 CVSS 3.0 High EPSS 2.9% · top 13.8% CWE-787 · Out-of-bounds write
8.8CVSS 3.0 base score, v2 6.8
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-19655 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.4CVE-2016-3714ImageMagick coders allow command execution via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 fail to validate input in multiple coders (EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, PLT), allo…KEVEPSS 97%analysed5.5CVE-2014-0196Linux kernel n_tty_write race condition allows local privilege escalationThe n_tty_write function in the Linux kernel through 3.14.3 mishandles tty driver access in the LECHO & !OPOST case, creating a race condition betwee…KEVEPSS 22%analysed10.0CVE-2015-2738Canonical ubuntu linux vulnerabilityThe YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8…EPSS 2.7%10.0CVE-2015-2737Mozilla firefox vulnerabilityThe rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before …EPSS 2.7%10.0CVE-2015-2734Suse linux enterprise desktop vulnerabilityThe CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 a…EPSS 2.7%10.0CVE-2015-0491Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and Java FX 2.2.76, allows remote attackers to affect confidentiality, inte…EPSS 5.6%10.0CVE-2015-3042Adobe flash player vulnerabilityAdobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…EPSS 37%10.0CVE-2015-3041Adobe flash player vulnerabilityAdobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…EPSS 6.0%

Source: NIST National Vulnerability Database (record CVE-2018-19655), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.