Home/Product/graphicsmagick
Product

graphicsmagick

123 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-32460
< 1.3.46
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea
4.0MEDIUM
CVE-2025-27796
< 1.3.46
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to hea
4.5MEDIUM
CVE-2025-27795
< 1.3.46
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
4.3MEDIUM
CVE-2020-21679
all versions
Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial o
5.5MEDIUM
CVE-2022-1270
all versions
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
7.8HIGH
CVE-2020-12672
<= 1.3.35
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
7.5HIGH
CVE-2020-10938
< 1.3.35
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/comp
9.8CRITICAL
CVE-2019-12921
< 1.3.32
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image b
6.5MEDIUM
CVE-2019-19953
all versions
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
9.1CRITICAL
CVE-2019-19951
all versions
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c
9.8CRITICAL
CVE-2019-19950
all versions
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c
9.8CRITICAL
CVE-2019-11506
all versions
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATL
8.8HIGH
CVE-2019-11505
>= 1.3.8 and <= 1.3.31
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBIm
8.8HIGH
CVE-2019-11474
all versions
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application cras
6.5MEDIUM
CVE-2019-11473
all versions
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by
6.5MEDIUM
CVE-2019-11010
<= 1.3.31
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows atta
6.5MEDIUM
CVE-2019-11009
<= 1.3.31
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, w
8.1HIGH
CVE-2019-11008
<= 1.3.31
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, w
8.8HIGH
CVE-2019-11007
<= 1.3.31
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, w
8.1HIGH
CVE-2019-11006
<= 1.3.31
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c,
9.1CRITICAL
CVE-2019-11005
<= 1.3.31
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c
9.8CRITICAL
CVE-2019-7397
<= 1.3.31
In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.
7.5HIGH
CVE-2018-20189
all versions
In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via
6.5MEDIUM
CVE-2018-20185
all versions
In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage functio
5.3MEDIUM
CVE-2018-20184
all versions
In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which al
6.5MEDIUM
CVE-2018-18544
< 1.3.31
There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScrip
6.5MEDIUM
CVE-2018-9018
all versions
In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage
6.5MEDIUM
CVE-2017-18231
all versions
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadEnhMetaFi
6.5MEDIUM
CVE-2017-18230
all versions
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONIma
6.5MEDIUM
CVE-2017-18229
all versions
An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in c
6.5MEDIUM
CVE-2017-18220
all versions
The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial o
8.8HIGH
CVE-2017-18219
all versions
An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in
6.5MEDIUM
CVE-2018-6799
< 1.3.28
The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial o
8.8HIGH
CVE-2018-5685
all versions
In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attac
6.5MEDIUM
CVE-2018-5360
all versions
LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage f
8.8HIGH
CVE-2017-17915
all versions
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to acc
8.8HIGH
CVE-2017-17913
all versions
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to
8.8HIGH
CVE-2017-17912
all versions
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which L
8.8HIGH
CVE-2017-17783
all versions
In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.
7.5HIGH
CVE-2017-17782
all versions
In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk alloca
8.8HIGH
CVE-2017-17503
all versions
ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read vi
8.8HIGH
CVE-2017-17502
all versions
ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read vi
8.8HIGH
CVE-2017-17501
all versions
WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.
8.8HIGH
CVE-2017-17500
all versions
ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a
8.8HIGH
CVE-2017-17498
all versions
WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBi
8.8HIGH
CVE-2017-16669
all versions
coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and applica
8.8HIGH
CVE-2017-16547
all versions
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated wit
8.8HIGH
CVE-2017-16545
all versions
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows rem
8.8HIGH
CVE-2017-16353
all versions
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the ma
6.5MEDIUM
CVE-2017-16352
all versions
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" fe
8.8HIGH
CVE-2017-15930
all versions
In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines,
8.8HIGH
CVE-2017-15277
all versions
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a G
6.5MEDIUM
CVE-2017-15238
all versions
ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to R
8.8HIGH
CVE-2017-14997
all versions
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer und
6.5MEDIUM
CVE-2017-14994
all versions
ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereferen
6.5MEDIUM
CVE-2017-14733
all versions
ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote atta
6.5MEDIUM
CVE-2017-14649
all versions
ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not properly validate JNG data, leading to a denial of servi
5.5MEDIUM
CVE-2017-14504
all versions
ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors for the XV 332 format, leading
6.5MEDIUM
CVE-2017-14314
all versions
Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial o
6.5MEDIUM
CVE-2017-14165
all versions
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has an issue where memory allocation is excessive because it de
6.5MEDIUM
CVE-2017-14103
all versions
The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers afte
8.8HIGH
CVE-2017-14042
all versions
A memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vulnerabilit
6.5MEDIUM
CVE-2017-13777
all versions
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case tha
6.5MEDIUM
CVE-2017-13776
all versions
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version!=10 case tha
6.5MEDIUM
CVE-2017-13775
all versions
GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/jnx.c whereby large amounts of CPU and memory reso
6.5MEDIUM
CVE-2017-13737
all versions
There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial
6.5MEDIUM
CVE-2017-13736
all versions
There are lots of memory leaks in the GMCommand function in magick/command.c in GraphicsMagick 1.3.26 that will lead to a remote d
6.5MEDIUM
CVE-2017-13648
all versions
In GraphicsMagick 1.3.26, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c.
6.5MEDIUM
CVE-2017-13147
all versions
In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c when a small
8.8HIGH
CVE-2017-13066
all versions
GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage in magick/image.c.
6.5MEDIUM
CVE-2017-13065
all versions
GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.
6.5MEDIUM
CVE-2017-13064
all versions
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.
6.5MEDIUM
CVE-2017-13063
all versions
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.
6.5MEDIUM
CVE-2017-12937
all versions
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.
8.8HIGH
CVE-2017-12936
all versions
The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception r
8.8HIGH
CVE-2017-12935
all versions
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read
8.8HIGH
CVE-2017-11722
all versions
The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-o
6.5MEDIUM
CVE-2017-11643
all versions
GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple frames that h
9.8CRITICAL
CVE-2017-11642
all versions
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() function in coders/map.c when processing a non-colorma
8.8HIGH
CVE-2017-11641
all versions
GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent C
9.8CRITICAL
CVE-2017-11638
all versions
GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() function in coders/map.c when processing a non-colormapp
8.8HIGH
CVE-2017-11637
all versions
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() function in coders/pcl.c during writes of monochrome i
9.8CRITICAL
CVE-2017-11636
all versions
GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that hav
9.8CRITICAL
CVE-2017-11403
all versions
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-fr
8.8HIGH
CVE-2017-11140
all versions
The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline,
5.5MEDIUM
CVE-2017-11139
all versions
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
9.8CRITICAL
CVE-2017-11102
all versions
The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (applic
7.5HIGH
CVE-2017-10800
all versions
When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if
5.5MEDIUM
CVE-2017-10799
all versions
When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OO
5.5MEDIUM
CVE-2017-10794
all versions
When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a
5.5MEDIUM
CVE-2017-9098
< 1.3.24
ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to l
7.5HIGH
CVE-2017-6335
<= 1.3.25
The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial o
5.5MEDIUM
CVE-2016-9830
all versions
The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via l
5.5MEDIUM
CVE-2016-5240
<= 1.3.23
The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote a
5.5MEDIUM
CVE-2016-8684
all versions
The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a cra
7.8HIGH
CVE-2016-8683
all versions
The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafte
7.8HIGH
CVE-2016-8682
all versions
The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service (out-of-bo
7.5HIGH
CVE-2016-7800
<= 1.3.25
Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause
7.5HIGH
CVE-2016-7449
all versions
The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-b
7.5HIGH
CVE-2016-7448
<= 1.3.24
The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large
7.5HIGH
CVE-2016-7447
<= 1.3.24
Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspe
9.8CRITICAL
CVE-2016-7446
all versions
Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via
9.8CRITICAL
CVE-2016-5241
<= 1.3.23
magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and app
5.5MEDIUM
CVE-2016-2318
all versions
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, rela
5.5MEDIUM
CVE-2016-2317
all versions
Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG f
5.5MEDIUM
CVE-2016-7997
<= 1.3.25
The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure
7.5HIGH
CVE-2016-7996
<= 1.3.25
Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecifi
9.8CRITICAL
CVE-2015-8808
<= 1.3.17
The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitiali
5.5MEDIUM
CVE-2016-5118
<= 1.3.23
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code
9.8CRITICAL
CVE-2013-4589
<= 1.3.17
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of
CVE-2012-3438
all versions
The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation
CVE-2008-6621
all versions
Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecif
CVE-2008-6072
<= 1.1.13
Multiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allow remote attackers to cause a de
CVE-2008-6071
<= 1.1.13
Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, a
CVE-2008-6070
<= 1.2.2
Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote a
CVE-2008-3134
all versions
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, in
CVE-2008-1097
all versions
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 an
CVE-2008-1096
all versions
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows us
CVE-2007-0770
all versions
Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly
CVE-2006-5456
<= 1.1.6
Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of
CVE-2005-1739
all versions
The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of se
CVE-2005-0005
all versions
Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute
CVE-2005-1275
all versions
Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to caus
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin