graphicsmagick CVE Vulnerabilities & Metrics

Focus on graphicsmagick vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About graphicsmagick Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with graphicsmagick. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total graphicsmagick CVEs: 106
Earliest CVE date: 25 Apr 2005, 04:00 UTC
Latest CVE date: 22 Aug 2023, 19:16 UTC

Latest CVE reference: CVE-2020-21679

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical graphicsmagick CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.73

Max CVSS: 10.0

Critical CVEs (≥9): 4

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 91
7.0-8.9 20
9.0-10.0 4

CVSS Distribution Chart

Top 5 Highest CVSS graphicsmagick CVEs

These are the five CVEs with the highest CVSS scores for graphicsmagick, sorted by severity first and recency.

All CVEs for graphicsmagick

CVE-2020-21679 graphicsmagick vulnerability CVSS: 0 22 Aug 2023, 19:16 UTC

Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.

CVE-2022-1270 graphicsmagick vulnerability CVSS: 0 28 Sep 2022, 20:15 UTC

In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.

CVE-2020-12672 graphicsmagick vulnerability CVSS: 5.0 06 May 2020, 03:15 UTC

GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.

CVE-2020-10938 graphicsmagick vulnerability CVSS: 7.5 24 Mar 2020, 16:15 UTC

GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

CVE-2019-12921 graphicsmagick vulnerability CVSS: 4.3 18 Mar 2020, 19:15 UTC

In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.

CVE-2019-19953 graphicsmagick vulnerability CVSS: 6.4 24 Dec 2019, 01:15 UTC

In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.

CVE-2019-19951 graphicsmagick vulnerability CVSS: 7.5 24 Dec 2019, 01:15 UTC

In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.

CVE-2019-19950 graphicsmagick vulnerability CVSS: 7.5 24 Dec 2019, 01:15 UTC

In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

CVE-2019-11506 graphicsmagick vulnerability CVSS: 6.8 24 Apr 2019, 21:29 UTC

In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in magick/export.c.

CVE-2019-11505 graphicsmagick vulnerability CVSS: 6.8 24 Apr 2019, 21:29 UTC

In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c.

CVE-2019-11474 graphicsmagick vulnerability CVSS: 4.3 23 Apr 2019, 14:29 UTC

coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.

CVE-2019-11473 graphicsmagick vulnerability CVSS: 4.3 23 Apr 2019, 14:29 UTC

coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.

CVE-2019-11010 graphicsmagick vulnerability CVSS: 4.3 08 Apr 2019, 19:29 UTC

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.

CVE-2019-11009 graphicsmagick vulnerability CVSS: 5.8 08 Apr 2019, 19:29 UTC

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.

CVE-2019-11008 graphicsmagick vulnerability CVSS: 6.8 08 Apr 2019, 19:29 UTC

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.

CVE-2019-11007 graphicsmagick vulnerability CVSS: 5.8 08 Apr 2019, 19:29 UTC

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.

CVE-2019-11006 graphicsmagick vulnerability CVSS: 6.4 08 Apr 2019, 19:29 UTC

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet.

CVE-2019-11005 graphicsmagick vulnerability CVSS: 7.5 08 Apr 2019, 19:29 UTC

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value.

CVE-2019-7397 graphicsmagick vulnerability CVSS: 5.0 05 Feb 2019, 00:29 UTC

In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.

CVE-2018-20189 graphicsmagick vulnerability CVSS: 4.3 17 Dec 2018, 20:29 UTC

In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization.

CVE-2018-20185 graphicsmagick vulnerability CVSS: 2.6 17 Dec 2018, 19:29 UTC

In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects GraphicsMagick installations with customized BMP limits.

CVE-2018-20184 graphicsmagick vulnerability CVSS: 4.3 17 Dec 2018, 19:29 UTC

In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.

CVE-2018-18544 graphicsmagick vulnerability CVSS: 4.3 21 Oct 2018, 01:29 UTC

There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.

CVE-2018-9018 graphicsmagick vulnerability CVSS: 4.3 25 Mar 2018, 21:29 UTC

In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.

CVE-2017-18231 graphicsmagick vulnerability CVSS: 4.3 14 Mar 2018, 02:29 UTC

An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadEnhMetaFile in coders/emf.c, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-18230 graphicsmagick vulnerability CVSS: 4.3 14 Mar 2018, 02:29 UTC

An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-18229 graphicsmagick vulnerability CVSS: 4.3 14 Mar 2018, 02:29 UTC

An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations.

CVE-2017-18220 graphicsmagick vulnerability CVSS: 6.8 05 Mar 2018, 22:29 UTC

The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c CloseBlob use-after-free) or possibly have unspecified other impact via a crafted file, a related issue to CVE-2017-11403.

CVE-2017-18219 graphicsmagick vulnerability CVSS: 4.3 05 Mar 2018, 22:29 UTC

An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted file that triggers an attempt at a large png_pixels array allocation.

CVE-2018-6799 graphicsmagick vulnerability CVSS: 6.8 07 Feb 2018, 05:29 UTC

The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.

CVE-2018-5685 graphicsmagick vulnerability CVSS: 4.3 14 Jan 2018, 02:29 UTC

In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with a crafted bit-field mask value.

CVE-2018-5360 graphicsmagick vulnerability CVSS: 6.8 14 Jan 2018, 02:29 UTC

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

CVE-2017-17915 graphicsmagick vulnerability CVSS: 6.8 27 Dec 2017, 17:08 UTC

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.

CVE-2017-17913 graphicsmagick vulnerability CVSS: 6.8 27 Dec 2017, 17:08 UTC

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type.

CVE-2017-17912 graphicsmagick vulnerability CVSS: 6.8 27 Dec 2017, 17:08 UTC

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region.

CVE-2017-17783 graphicsmagick vulnerability CVSS: 5.1 20 Dec 2017, 09:29 UTC

In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.

CVE-2017-17782 graphicsmagick vulnerability CVSS: 6.8 20 Dec 2017, 09:29 UTC

In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.

CVE-2017-17503 graphicsmagick vulnerability CVSS: 6.8 11 Dec 2017, 02:29 UTC

ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.

CVE-2017-17502 graphicsmagick vulnerability CVSS: 6.8 11 Dec 2017, 02:29 UTC

ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.

CVE-2017-17501 graphicsmagick vulnerability CVSS: 6.8 11 Dec 2017, 02:29 UTC

WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.

CVE-2017-17500 graphicsmagick vulnerability CVSS: 6.8 11 Dec 2017, 02:29 UTC

ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file.

CVE-2017-17498 graphicsmagick vulnerability CVSS: 6.8 11 Dec 2017, 02:29 UTC

WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBitStreamMSBWrite heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

CVE-2017-16669 graphicsmagick vulnerability CVSS: 6.8 09 Nov 2017, 00:29 UTC

coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.

CVE-2017-16547 graphicsmagick vulnerability CVSS: 6.8 06 Nov 2017, 05:29 UTC

The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.

CVE-2017-16545 graphicsmagick vulnerability CVSS: 6.8 05 Nov 2017, 22:29 UTC

The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType invalid write and application crash) or possibly have unspecified other impact via a malformed WPG image.

CVE-2017-16353 graphicsmagick vulnerability CVSS: 4.3 01 Nov 2017, 15:29 UTC

GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is responsible for printing the IPTC Profile information contained in the image. This vulnerability can be triggered with a specially crafted MIFF file. There is an out-of-bounds buffer dereference because certain increments are never checked.

CVE-2017-16352 graphicsmagick vulnerability CVSS: 6.8 01 Nov 2017, 15:29 UTC

GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magick/describe.c file. One possible way to trigger the vulnerability is to run the identify command on a specially crafted MIFF format file with the verbose flag.

CVE-2017-15930 graphicsmagick vulnerability CVSS: 6.8 27 Oct 2017, 18:29 UTC

In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer.

CVE-2017-15277 graphicsmagick vulnerability CVSS: 4.3 12 Oct 2017, 08:29 UTC

ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.

CVE-2017-15238 graphicsmagick vulnerability CVSS: 6.8 11 Oct 2017, 03:29 UTC

ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.

CVE-2017-14997 graphicsmagick vulnerability CVSS: 7.1 04 Oct 2017, 01:29 UTC

GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.

CVE-2017-14994 graphicsmagick vulnerability CVSS: 4.3 04 Oct 2017, 01:29 UTC

ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield an image list with zero frames.

CVE-2017-14733 graphicsmagick vulnerability CVSS: 4.3 25 Sep 2017, 21:29 UTC

ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

CVE-2017-14649 graphicsmagick vulnerability CVSS: 4.3 21 Sep 2017, 17:29 UTC

ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not properly validate JNG data, leading to a denial of service (assertion failure in magick/pixel_cache.c, and application crash).

CVE-2017-14504 graphicsmagick vulnerability CVSS: 4.3 17 Sep 2017, 19:29 UTC

ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors for the XV 332 format, leading to a NULL Pointer Dereference.

CVE-2017-14314 graphicsmagick vulnerability CVSS: 4.3 12 Sep 2017, 00:29 UTC

Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDashPolygon heap-based buffer over-read and application crash) via a crafted file.

CVE-2017-14165 graphicsmagick vulnerability CVSS: 4.3 06 Sep 2017, 18:29 UTC

The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has an issue where memory allocation is excessive because it depends only on a length field in a header. This may lead to remote denial of service in the MagickMalloc function in magick/memory.c.

CVE-2017-14103 graphicsmagick vulnerability CVSS: 6.8 01 Sep 2017, 13:29 UTC

The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote attackers to conduct use-after-free attacks via a crafted file, related to a ReadMNGImage out-of-order CloseBlob call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-11403.

CVE-2017-14042 graphicsmagick vulnerability CVSS: 4.3 30 Aug 2017, 22:29 UTC

A memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vulnerability causes a big memory allocation, which may lead to remote denial of service in the MagickRealloc function in magick/memory.c.

CVE-2017-13777 graphicsmagick vulnerability CVSS: 7.1 30 Aug 2017, 09:29 UTC

GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.

CVE-2017-13776 graphicsmagick vulnerability CVSS: 7.1 30 Aug 2017, 09:29 UTC

GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version!=10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.

CVE-2017-13775 graphicsmagick vulnerability CVSS: 7.1 30 Aug 2017, 09:29 UTC

GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/jnx.c whereby large amounts of CPU and memory resources may be consumed although the file itself does not support the requests.

CVE-2017-13737 graphicsmagick vulnerability CVSS: 4.3 29 Aug 2017, 06:29 UTC

There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.

CVE-2017-13736 graphicsmagick vulnerability CVSS: 4.3 29 Aug 2017, 06:29 UTC

There are lots of memory leaks in the GMCommand function in magick/command.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.

CVE-2017-13648 graphicsmagick vulnerability CVSS: 4.3 23 Aug 2017, 21:29 UTC

In GraphicsMagick 1.3.26, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c.

CVE-2017-13147 graphicsmagick vulnerability CVSS: 6.8 23 Aug 2017, 17:29 UTC

In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c when a small MNG file has a MEND chunk with a large length value.

CVE-2017-13066 graphicsmagick vulnerability CVSS: 4.3 22 Aug 2017, 06:29 UTC

GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage in magick/image.c.

CVE-2017-13065 graphicsmagick vulnerability CVSS: 4.3 22 Aug 2017, 06:29 UTC

GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.

CVE-2017-13064 graphicsmagick vulnerability CVSS: 4.3 22 Aug 2017, 06:29 UTC

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.

CVE-2017-13063 graphicsmagick vulnerability CVSS: 4.3 22 Aug 2017, 06:29 UTC

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.

CVE-2017-12937 graphicsmagick vulnerability CVSS: 6.8 18 Aug 2017, 12:29 UTC

The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.

CVE-2017-12936 graphicsmagick vulnerability CVSS: 6.8 18 Aug 2017, 12:29 UTC

The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.

CVE-2017-12935 graphicsmagick vulnerability CVSS: 6.8 18 Aug 2017, 12:29 UTC

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.

CVE-2017-11722 graphicsmagick vulnerability CVSS: 4.3 28 Jul 2017, 13:29 UTC

The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its indentation. This resulted in a logging statement executing outside of a loop, and consequently using an invalid array index corresponding to the loop's exit condition.

CVE-2017-11643 graphicsmagick vulnerability CVSS: 7.5 26 Jul 2017, 08:29 UTC

GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple frames that have non-identical widths.

CVE-2017-11642 graphicsmagick vulnerability CVSS: 6.8 26 Jul 2017, 08:29 UTC

GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11638.

CVE-2017-11641 graphicsmagick vulnerability CVSS: 7.5 26 Jul 2017, 08:29 UTC

GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.

CVE-2017-11638 graphicsmagick vulnerability CVSS: 6.8 26 Jul 2017, 08:29 UTC

GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11642.

CVE-2017-11637 graphicsmagick vulnerability CVSS: 7.5 26 Jul 2017, 08:29 UTC

GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() function in coders/pcl.c during writes of monochrome images.

CVE-2017-11636 graphicsmagick vulnerability CVSS: 7.5 26 Jul 2017, 08:29 UTC

GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widths.

CVE-2017-11403 graphicsmagick vulnerability CVSS: 6.8 18 Jul 2017, 00:29 UTC

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.

CVE-2017-11140 graphicsmagick vulnerability CVSS: 7.1 10 Jul 2017, 03:29 UTC

The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.

CVE-2017-11139 graphicsmagick vulnerability CVSS: 7.5 10 Jul 2017, 03:29 UTC

GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.

CVE-2017-11102 graphicsmagick vulnerability CVSS: 5.0 07 Jul 2017, 18:29 UTC

The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (application crash) during JNG reading via a zero-length color_image data structure.

CVE-2017-10800 graphicsmagick vulnerability CVSS: 4.3 03 Jul 2017, 01:29 UTC

When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data.

CVE-2017-10799 graphicsmagick vulnerability CVSS: 4.3 03 Jul 2017, 01:29 UTC

When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().

CVE-2017-10794 graphicsmagick vulnerability CVSS: 4.3 02 Jul 2017, 22:29 UTC

When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode.

CVE-2017-9098 graphicsmagick vulnerability CVSS: 5.0 19 May 2017, 19:29 UTC

ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initialization step in the ReadRLEImage function in coders/rle.c.

CVE-2017-6335 graphicsmagick vulnerability CVSS: 4.3 14 Mar 2017, 14:59 UTC

The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samples per pixel value in a CMYKA TIFF file.

CVE-2016-9830 graphicsmagick vulnerability CVSS: 4.3 01 Mar 2017, 20:59 UTC

The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via large dimensions in a jpeg image.

CVE-2016-5240 graphicsmagick vulnerability CVSS: 4.3 27 Feb 2017, 22:59 UTC

The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.

CVE-2016-8684 graphicsmagick vulnerability CVSS: 6.8 15 Feb 2017, 19:59 UTC

The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure and a "file truncation error for corrupt file."

CVE-2016-8683 graphicsmagick vulnerability CVSS: 6.8 15 Feb 2017, 19:59 UTC

The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure and a "file truncation error for corrupt file."

CVE-2016-8682 graphicsmagick vulnerability CVSS: 5.0 15 Feb 2017, 19:59 UTC

The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted SCT header.

CVE-2016-7800 graphicsmagick vulnerability CVSS: 5.0 06 Feb 2017, 17:59 UTC

Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM chunk, which triggers a heap-based buffer overflow.

CVE-2016-7449 graphicsmagick vulnerability CVSS: 5.0 06 Feb 2017, 17:59 UTC

The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a file containing an "unterminated" string.

CVE-2016-7448 graphicsmagick vulnerability CVSS: 7.8 06 Feb 2017, 17:59 UTC

The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size.

CVE-2016-7447 graphicsmagick vulnerability CVSS: 7.5 06 Feb 2017, 17:59 UTC

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.

CVE-2016-7446 graphicsmagick vulnerability CVSS: 7.5 06 Feb 2017, 17:59 UTC

Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete patch for CVE-2016-2317.

CVE-2016-5241 graphicsmagick vulnerability CVSS: 4.3 03 Feb 2017, 15:59 UTC

magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file.

CVE-2016-2318 graphicsmagick vulnerability CVSS: 4.3 03 Feb 2017, 15:59 UTC

GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c.

CVE-2016-2317 graphicsmagick vulnerability CVSS: 4.3 03 Feb 2017, 15:59 UTC

Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c.

CVE-2016-7997 graphicsmagick vulnerability CVSS: 5.0 18 Jan 2017, 17:59 UTC

The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer.

CVE-2016-7996 graphicsmagick vulnerability CVSS: 7.5 18 Jan 2017, 17:59 UTC

Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.

CVE-2015-8808 graphicsmagick vulnerability CVSS: 4.3 13 Jul 2016, 15:59 UTC

The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file.

CVE-2016-5118 graphicsmagick vulnerability CVSS: 10.0 10 Jun 2016, 15:59 UTC

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

CVE-2013-4589 graphicsmagick vulnerability CVSS: 4.3 23 Nov 2013, 11:55 UTC

The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.

CVE-2012-3438 graphicsmagick vulnerability CVSS: 4.3 07 Aug 2012, 21:55 UTC

The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.

CVE-2008-6621 graphicsmagick vulnerability CVSS: 7.8 06 Apr 2009, 21:30 UTC

Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information.

CVE-2008-6072 graphicsmagick vulnerability CVSS: 5.0 10 Feb 2009, 06:59 UTC

Multiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allow remote attackers to cause a denial of service (crash) via unspecified vectors in (1) XCF and (2) CINEON images.

CVE-2008-6071 graphicsmagick vulnerability CVSS: 10.0 10 Feb 2009, 06:59 UTC

Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PICT image. NOTE: some of these details are obtained from third party information.

CVE-2008-6070 graphicsmagick vulnerability CVSS: 9.3 10 Feb 2009, 06:59 UTC

Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PALM image, a different vulnerability than CVE-2007-0770. NOTE: some of these details are obtained from third party information.

CVE-2008-3134 graphicsmagick vulnerability CVSS: 5.0 10 Jul 2008, 23:41 UTC

Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.

CVE-2007-0770 graphicsmagick vulnerability CVSS: 9.3 12 Feb 2007, 20:28 UTC

Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.

CVE-2006-5456 graphicsmagick vulnerability CVSS: 5.1 23 Oct 2006, 17:07 UTC

Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.

CVE-2005-1739 graphicsmagick vulnerability CVSS: 5.0 24 May 2005, 04:00 UTC

The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.

CVE-2005-0005 graphicsmagick vulnerability CVSS: 7.5 02 May 2005, 04:00 UTC

Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.

CVE-2005-1275 graphicsmagick vulnerability CVSS: 5.0 25 Apr 2005, 04:00 UTC

Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.