← Back

Libgd

libgd

39 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Libgd
libgd

CVEs (39)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
LibgdPhp
3Debian Linux
LibgdPhp
May 6, 2026
Sep 28, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer ov...Show more
Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.Show less
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
4Debian
LibgdOpensuse+1 more
4Debian Linux
LeapLibgd+1 more
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory cons...Show more
Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.Show less
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
4Canonical
DebianLibgd+1 more
4Debian Linux
LeapLibgd+1 more
May 6, 2026
Aug 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid col...Show more
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.Show less
1Libgd
1Libgd
May 6, 2026
Aug 7, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the gdImageCreate function in gd.c in the GD Graphics Library (aka libgd) before 2.0.34RC1, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a...Show more
Integer overflow in the gdImageCreate function in gd.c in the GD Graphics Library (aka libgd) before 2.0.34RC1, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted image dimensions.Show less
5Debian
FedoraprojectFreebsd+2 more
6Debian Linux
Enterprise LinuxFedora+3 more
May 6, 2026
Aug 7, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a...Show more
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.Show less
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 7, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial o...Show more
gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.Show less
1Libgd
1Libgd
May 6, 2026
Aug 7, 2016
N/A· v4
7.6 HIGH· v3
6.8 MEDIUM· v2
gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a denial of service (out-of-bounds read) o...Show more
gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted image that is mishandled by the imagescale function.Show less
2Libgd
Php
2Libgd
Php
May 6, 2026
May 22, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses inconsistent allocate and free approaches, which allows remote attackers to c...Show more
The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses inconsistent allocate and free approaches, which allows remote attackers to cause a denial of service (memory consumption) via a crafted call, as demonstrated by a call to the PHP imagescale function.Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLibgd+3 more
May 6, 2026
Apr 26, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which trigge...Show more
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.Show less
5Canonical
DebianLibgd+2 more
5Debian Linux
LibgdOpensuse+2 more
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a craft...Show more
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.Show less
2Libgd
Php
2Gd Graphics Library
Php
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct b...Show more
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.Show less
1Libgd
1Gd Graphics Library
Apr 23, 2026
Jun 28, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value.
1Libgd
1Gd Graphics Library
Apr 23, 2026
Jun 28, 2007
N/A· v4
N/A· v3
2.6 LOW· v2
Multiple unspecified vulnerabilities in the GIF reader in the GD Graphics Library (libgd) before 2.0.35 have unspecified impact and user-assisted remote attack vectors.
1Libgd
1Gd Graphics Library
Apr 23, 2026
Jun 28, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure.
1Libgd
1Gd Graphics Library
Apr 23, 2026
Jun 28, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Integer overflow in gdImageCreateTrueColor function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to have unspecified attack vectors and impact.
1Libgd
1Libgd
Apr 23, 2026
May 18, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info fun...Show more
The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.Show less