📦

pillow

Vendor: python

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 15 Remote Access
Total CVEs 145 Total Indexed
Avg. EPSS 1.95% Exploit Prob.
Latest CVE CVE-2026-59200 Jul 14

Security Vulnerability Index

Page 6 / 15
7.8 CVSS

In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.

EPSS: 1.13%
5.5 CVSS

In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.

EPSS: 1.10%
5.5 CVSS

Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.

EPSS: 1.47%
7.5 CVSS

There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.

EPSS: 2.12%
7.1 CVSS

libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.

EPSS: 2.75%
9.8 CVSS

libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

EPSS: 3.69%
9.8 CVSS

libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.

EPSS: 4.21%
8.8 CVSS

libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.

EPSS: 1.98%
7.5 CVSS

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.

EPSS: 3.15%
5.5 CVSS

Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.

EPSS: 2.56%