CVE-2018-19566: Dcraw Project Dcraw

High severity, CVSS 7.1. EPSS: 1.1% chance of exploitation in the next 30 days.

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

Affected products

Published 2018-11-26. Last modified 2026-06-17.