pillow vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the pillow package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
CVE-2024-28219

<2.3.0-1ubuntu3.4+esm4
  • M
Improper Initialization

<2.3.0-1ubuntu3.4+esm3
  • L
Out-of-bounds Read

<2.3.0-1ubuntu3.4+esm3
  • M
CVE-2022-22817

*
  • L
Out-of-bounds Read

<2.3.0-1ubuntu3.4+esm3
  • L
Buffer Overflow

<2.3.0-1ubuntu3.4+esm3
  • M
Out-of-bounds Read

<2.3.0-1ubuntu3.4+esm2
  • L
Out-of-bounds Read

<2.3.0-1ubuntu3.4+esm2
  • L
Integer Overflow or Wraparound

<2.3.0-1ubuntu3.4+esm1
  • M
Buffer Overflow

<2.3.0-1ubuntu3.4+esm1
  • M
Out-of-bounds Read

<2.3.0-1ubuntu3.4+esm1
  • L
Allocation of Resources Without Limits or Throttling

<2.3.0-1ubuntu3.4+esm1
  • M
Improper Access Control

<2.3.0-1ubuntu3.4
  • M
Integer Overflow or Wraparound

<2.3.0-1ubuntu3.4
  • M
Out-of-Bounds

<2.3.0-1ubuntu3.2
  • M
Out-of-Bounds

<2.3.0-1ubuntu3.2
  • M
Out-of-Bounds

<2.3.0-1ubuntu3.2
  • L
Improper Input Validation

<2.3.0-1ubuntu3.4
  • L
Improper Input Validation

<2.3.0-1ubuntu3.2
  • M
OS Command Injection

<2.3.0-1ubuntu3