[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2017-6886":6},{"stargazers_count":4,"fetched_at":5},5,"2026-04-08T14:11:31.067Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":68,"aliases":69,"duplicate_of":9,"upstream":70,"downstream":71,"duplicates":88,"related":89,"reserved_at":9,"published_at":94,"modified_at":95,"state":96,"summary":97,"references_raw":106,"kevs":137,"epss":138,"epss_history":141,"metrics":396,"affected":405},"CVE-2017-6886","An error within the \"parse_tiff_ifd()\" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-119","Improper Restriction of Operations within the Bounds of a Memory Buffer","The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.","weakness","Stable","Class","High",[20,24,28,32,36,40,44,48,52,56,60,64],{"id":21,"name":22,"techniques":23},"CAPEC-10","Buffer Overflow via Environment Variables",[],{"id":25,"name":26,"techniques":27},"CAPEC-100","Overflow Buffers",[],{"id":29,"name":30,"techniques":31},"CAPEC-123","Buffer Manipulation",[],{"id":33,"name":34,"techniques":35},"CAPEC-14","Client-side Injection-induced Buffer Overflow",[],{"id":37,"name":38,"techniques":39},"CAPEC-24","Filter Failure through Buffer Overflow",[],{"id":41,"name":42,"techniques":43},"CAPEC-42","MIME Conversion",[],{"id":45,"name":46,"techniques":47},"CAPEC-44","Overflow Binary Resource File",[],{"id":49,"name":50,"techniques":51},"CAPEC-45","Buffer Overflow via Symbolic Links",[],{"id":53,"name":54,"techniques":55},"CAPEC-46","Overflow Variables and Tags",[],{"id":57,"name":58,"techniques":59},"CAPEC-47","Buffer Overflow via Parameter Expansion",[],{"id":61,"name":62,"techniques":63},"CAPEC-8","Buffer Overflow in an API Call",[],{"id":65,"name":66,"techniques":67},"CAPEC-9","Buffer Overflow in Local Command-Line Utilities",[],[],[],[],[72,74,76,78,80,82,84,86],{"_key":73},"ALPINE-CVE-2017-6886",{"_key":75},"DEBIAN-CVE-2017-6886",{"_key":77},"SUSE-SU-2017:2300-1",{"_key":79},"UBUNTU-CVE-2017-6886",{"_key":81},"USN-3492-1",{"_key":83},"OPENSUSE-SU-2024:10980-1",{"_key":85},"DLA-1057-1",{"_key":87},"DSA-3950-1",[],[90,92,93],{"_key":91},"MGASA-2017-0223",{"_key":77},{"_key":83},"2017-05-16T15:00:00.000Z","2024-08-05T15:41:17.677Z","Deferred",{"cisa_kev":98,"cisa_ransomware":98,"cisa_vendor":9,"epss_severity":99,"epss_score":100,"severity":101,"severity_score":102,"severity_version":103,"severity_source":104,"severity_vector":105,"severity_status":96},false,"low",0.0058,"critical",9.8,"v3.0","nvd","CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[107,115,121,127,131],{"url":108,"sources":109,"tags":111},"https://github.com/LibRaw/LibRaw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251",[110,104],"cve.org",[112,113,114],"X Refsource CONFIRM","Patch","Third Party Advisory",{"url":116,"sources":117,"tags":118},"https://secuniaresearch.flexerasoftware.com/secunia_research/2017-5/",[110,104],[119,120,114],"X Refsource MISC","Permissions Required",{"url":122,"sources":123,"tags":124},"http://www.securityfocus.com/bid/98605",[110,104],[125,126,114],"VDB Entry","X Refsource BID",{"url":128,"sources":129,"tags":130},"https://secuniaresearch.flexerasoftware.com/advisories/75737/",[110,104],[119,120,114],{"url":132,"sources":133,"tags":134},"http://www.debian.org/security/2017/dsa-3950",[110,104],[135,136],"Vendor Advisory","X Refsource DEBIAN",[],{"date":139,"score":100,"percentile":140},"2026-04-07",0.68843,[142,145,148,151,154,157,160,163,165,168,171,174,176,179,181,185,188,191,194,197,200,202,205,208,211,214,216,218,221,224,227,230,233,236,238,240,243,246,249,252,255,258,260,263,265,268,271,274,276,279,282,285,288,290,293,296,298,301,304,307,310,312,315,318,320,323,326,329,332,335,338,341,344,347,350,353,356,358,361,364,367,370,373,376,379,382,385,388,391,393],{"date":143,"score":100,"percentile":144},"2025-11-04",0.68002,{"date":146,"score":100,"percentile":147},"2025-11-05",0.67981,{"date":149,"score":100,"percentile":150},"2025-11-06",0.67984,{"date":152,"score":100,"percentile":153},"2025-11-07",0.67995,{"date":155,"score":100,"percentile":156},"2025-11-08",0.67997,{"date":158,"score":100,"percentile":159},"2025-11-09",0.67987,{"date":161,"score":100,"percentile":162},"2025-11-10",0.67977,{"date":164,"score":100,"percentile":150},"2025-11-11",{"date":166,"score":100,"percentile":167},"2025-11-12",0.68007,{"date":169,"score":100,"percentile":170},"2025-11-13",0.68016,{"date":172,"score":100,"percentile":173},"2025-11-14",0.68023,{"date":175,"score":100,"percentile":173},"2025-11-15",{"date":177,"score":100,"percentile":178},"2025-11-16",0.6802,{"date":180,"score":100,"percentile":170},"2025-11-17",{"date":182,"score":183,"percentile":184},"2025-11-18",0.01237,0.77447,{"date":186,"score":183,"percentile":187},"2025-11-19",0.77454,{"date":189,"score":183,"percentile":190},"2025-11-20",0.77464,{"date":192,"score":100,"percentile":193},"2025-11-21",0.68035,{"date":195,"score":100,"percentile":196},"2025-11-22",0.68037,{"date":198,"score":100,"percentile":199},"2025-11-23",0.68026,{"date":201,"score":100,"percentile":170},"2025-11-24",{"date":203,"score":100,"percentile":204},"2025-11-25",0.68025,{"date":206,"score":100,"percentile":207},"2025-11-26",0.68032,{"date":209,"score":100,"percentile":210},"2025-11-27",0.68034,{"date":212,"score":100,"percentile":213},"2025-11-28",0.68019,{"date":215,"score":100,"percentile":144},"2025-11-29",{"date":217,"score":100,"percentile":156},"2025-11-30",{"date":219,"score":100,"percentile":220},"2025-12-01",0.6815,{"date":222,"score":100,"percentile":223},"2025-12-02",0.68157,{"date":225,"score":100,"percentile":226},"2025-12-03",0.68154,{"date":228,"score":100,"percentile":229},"2025-12-04",0.67988,{"date":231,"score":100,"percentile":232},"2025-12-05",0.68001,{"date":234,"score":100,"percentile":235},"2025-12-06",0.68005,{"date":237,"score":100,"percentile":144},"2025-12-07",{"date":239,"score":100,"percentile":235},"2025-12-08",{"date":241,"score":100,"percentile":242},"2025-12-09",0.68036,{"date":244,"score":100,"percentile":245},"2025-12-10",0.68082,{"date":247,"score":100,"percentile":248},"2025-12-11",0.68102,{"date":250,"score":100,"percentile":251},"2025-12-12",0.68127,{"date":253,"score":100,"percentile":254},"2025-12-13",0.68135,{"date":256,"score":100,"percentile":257},"2025-12-14",0.68138,{"date":259,"score":100,"percentile":254},"2025-12-15",{"date":261,"score":100,"percentile":262},"2025-12-16",0.68142,{"date":264,"score":100,"percentile":226},"2025-12-17",{"date":266,"score":100,"percentile":267},"2025-12-18",0.68188,{"date":269,"score":100,"percentile":270},"2025-12-19",0.68206,{"date":272,"score":100,"percentile":273},"2025-12-20",0.68204,{"date":275,"score":100,"percentile":267},"2025-12-21",{"date":277,"score":100,"percentile":278},"2025-12-22",0.68187,{"date":280,"score":100,"percentile":281},"2025-12-23",0.68184,{"date":283,"score":100,"percentile":284},"2025-12-24",0.68193,{"date":286,"score":100,"percentile":287},"2025-12-25",0.68224,{"date":289,"score":100,"percentile":287},"2025-12-26",{"date":291,"score":100,"percentile":292},"2025-12-27",0.68273,{"date":294,"score":100,"percentile":295},"2025-12-28",0.68196,{"date":297,"score":100,"percentile":267},"2025-12-29",{"date":299,"score":100,"percentile":300},"2025-12-30",0.68202,{"date":302,"score":100,"percentile":303},"2025-12-31",0.6822,{"date":305,"score":100,"percentile":306},"2026-01-01",0.68398,{"date":308,"score":100,"percentile":309},"2026-01-02",0.68385,{"date":311,"score":100,"percentile":309},"2026-01-03",{"date":313,"score":100,"percentile":314},"2026-01-04",0.68221,{"date":316,"score":100,"percentile":317},"2026-01-05",0.6821,{"date":319,"score":100,"percentile":303},"2026-01-06",{"date":321,"score":100,"percentile":322},"2026-01-07",0.68239,{"date":324,"score":100,"percentile":325},"2026-01-08",0.68255,{"date":327,"score":100,"percentile":328},"2026-01-09",0.68263,{"date":330,"score":100,"percentile":331},"2026-01-10",0.68264,{"date":333,"score":100,"percentile":334},"2026-01-11",0.68257,{"date":336,"score":100,"percentile":337},"2026-01-12",0.68246,{"date":339,"score":100,"percentile":340},"2026-01-13",0.68244,{"date":342,"score":100,"percentile":343},"2026-01-14",0.68281,{"date":345,"score":100,"percentile":346},"2026-01-15",0.68287,{"date":348,"score":100,"percentile":349},"2026-01-16",0.68303,{"date":351,"score":100,"percentile":352},"2026-01-17",0.68296,{"date":354,"score":100,"percentile":355},"2026-01-18",0.68285,{"date":357,"score":100,"percentile":292},"2026-01-19",{"date":359,"score":100,"percentile":360},"2026-01-20",0.68284,{"date":362,"score":100,"percentile":363},"2026-01-21",0.68292,{"date":365,"score":100,"percentile":366},"2026-01-22",0.68302,{"date":368,"score":100,"percentile":369},"2026-01-23",0.6833,{"date":371,"score":100,"percentile":372},"2026-01-24",0.6834,{"date":374,"score":100,"percentile":375},"2026-01-25",0.68312,{"date":377,"score":100,"percentile":378},"2026-01-26",0.68304,{"date":380,"score":100,"percentile":381},"2026-01-27",0.68308,{"date":383,"score":100,"percentile":384},"2026-01-28",0.6832,{"date":386,"score":100,"percentile":387},"2026-01-29",0.68319,{"date":389,"score":100,"percentile":390},"2026-01-30",0.68325,{"date":392,"score":100,"percentile":369},"2026-01-31",{"date":394,"score":100,"percentile":395},"2026-02-01",0.68481,[397],{"source":104,"cvss_v2_0":398,"cvss_v3_0":403,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":399,"baseSeverity":9,"vectorString":400,"impactScore":401,"exploitabilityScore":402},7.5,"AV:N/AC:L/Au:N/C:P/I:P/A:P",6.4,10,{"baseScore":102,"baseSeverity":404,"vectorString":105,"impactScore":102,"exploitabilityScore":402},"CRITICAL",[406],{"ecosystem":9,"name":407,"vendor":408,"product":408,"cpe_part":409,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":410},"LibRaw","libraw","a",[411,417],{"version":412,"is_range":413,"range_type":414,"version_start":9,"version_start_type":9,"version_end":415,"version_end_type":416,"fixed_in":9},"lte0.18.1",true,"cpe","0.18.1","including",{"version":418,"is_range":98,"range_type":110,"version_start":418,"version_start_type":416,"version_end":418,"version_end_type":416,"fixed_in":9},"0.x prior to 0.18.2"]