CVEs (121)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian GraphicsmagickOpensuse4Debian Linux GraphicsmagickLeap+1 moreMay 13, 2026 Feb 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors. |
3Debian GraphicsmagickOpensuse4Debian Linux GraphicsmagickLeap+1 moreMay 13, 2026 Feb 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete patch for CVE-2016-2...Show more |
3Debian GraphicsmagickOpensuse4Debian Linux GraphicsmagickLeap+1 moreMay 13, 2026 Feb 3, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file. |
4Debian GraphicsmagickOpensuse+1 more7Debian Linux GraphicsmagickLeap+4 moreMay 13, 2026 Feb 3, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in code...Show more |
4Debian GraphicsmagickOpensuse+1 more7Debian Linux GraphicsmagickLeap+4 moreMay 13, 2026 Feb 3, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in m...Show more |
1Graphicsmagick 1Graphicsmagick May 13, 2026 Jan 18, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer. |
1Graphicsmagick 1Graphicsmagick May 13, 2026 Jan 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries. |
3Fedoraproject GraphicsmagickSuse5Fedora GraphicsmagickLinux Enterprise Debuginfo+2 moreMay 6, 2026 Jul 13, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file. |
7Canonical DebianGraphicsmagick+4 more14Debian Linux GraphicsmagickImagemagick+11 moreMay 6, 2026 Jun 10, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename. |
3Fedoraproject GraphicsmagickNovell5Fedora GraphicsmagickSuse Linux Enterprise Debuginfo+2 moreApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image. |
The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafte...Show more |
Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party info...Show more |
Multiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allow remote attackers to cause a denial of service (crash) via unspecified vectors in (1) XCF and (2) CINEON images. |
Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary...Show more |
Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cra...Show more |
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (...Show more |
2Graphicsmagick Imagemagick2Graphicsmagick ImagemagickApr 23, 2026 Feb 12, 2007 N/A· v4 N/A· v3 9.3 HIGH· v2 Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage...Show more |
2Graphicsmagick Imagemagick2Graphicsmagick ImagemagickApr 23, 2026 Oct 23, 2006 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handl...Show more |
2Graphicsmagick Imagemagick2Graphicsmagick ImagemagickApr 16, 2026 May 24, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask. |
6Debian GentooGraphicsmagick+3 more6Debian Linux GraphicsmagickImagemagick+3 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers. |