The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers an out-of-bounds read.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3994.json"