← Vulnerability feed

Vulnerability record · CVE-2021-40263 · published 22 August 2023

CVE-2021-40263: Freeimage project freeimage out-of-bounds write vulnerability

Freeimage Project · Freeimage

A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad function in PluginTIFF.cpp.

8.8 CVSS 3.1 High EPSS 1.2% · top 34.1% CWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad function in PluginTIFF.cpp.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40263 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-70968Freeimage project freeimage use after free vulnerabilityFreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().EPSS 0.51%9.8CVE-2024-31570Freeimage project freeimage out-of-bounds write vulnerabilitylibfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.EPSS 0.61%8.8CVE-2023-47992Freeimage project freeimage integer overflow vulnerabilityAn integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a d…EPSS 0.72%8.8CVE-2023-47994Freeimage project freeimage integer overflow vulnerabilityAn integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information…EPSS 0.72%8.8CVE-2021-40265Freeimage project freeimage out-of-bounds write vulnerabilityA heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp.EPSS 0.89%8.8CVE-2020-24292Freeimage project freeimage classic buffer overflow vulnerabilityBuffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening…EPSS 1.5%8.8CVE-2020-24293Freeimage project freeimage classic buffer overflow vulnerabilityBuffer Overflow vulnerability in psdThumbnail::Read in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via op…EPSS 1.5%8.8CVE-2020-24295Freeimage project freeimage classic buffer overflow vulnerabilityBuffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in FreeImage 3.19.0 [r1859] allows remote attackers to ru narbitrary code via use of …EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-40263), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.