Debian Graphicsmagick vulnerabilities
141 known vulnerabilities affecting debian/graphicsmagick.
Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH47MEDIUM56LOW21
Vulnerabilities
Page 1 of 8
CVE-2016-3714P1HIGHCVSS 8.4KEVPoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3714 [HIGH] CVE-2016-3714: graphicsmagick - The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and...
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: r
debian
CVE-2016-3715P1MEDIUMCVSS 5.5KEVPoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3715 [MEDIUM] CVE-2016-3715: graphicsmagick - The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows...
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3.24-1)
debian
CVE-2016-3718P2MEDIUMCVSS 5.5KEVPoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3718 [MEDIUM] CVE-2016-3718: graphicsmagick - The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7....
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved
debian
CVE-2017-16352P2HIGHCVSS 8.8PoCfixed in graphicsmagick 1.3.26-17 (bookworm)2017
CVE-2017-16352 [HIGH] CVE-2017-16352: graphicsmagick - GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerabilit...
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magick/describe.c file. One possible way to trigger the vulnerability is to run the identify command on a specially crafted MIFF format file with the verbose flag.
Scope: local
bookworm:
debian
CVE-2016-5118P2CRITICALCVSS 9.8fixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-5118 [CRITICAL] CVE-2016-5118: graphicsmagick - The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick ...
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolve
debian
CVE-2016-3717P3MEDIUMCVSS 5.5PoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3717 [MEDIUM] CVE-2016-3717: graphicsmagick - The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows rem...
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3.24-1)
debian
CVE-2017-16353P3MEDIUMCVSS 6.5PoCfixed in graphicsmagick 1.3.26-17 (bookworm)2017
CVE-2017-16353 [MEDIUM] CVE-2017-16353: graphicsmagick - GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerabi...
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is responsible for printing the IPTC Profile information contained in the image. This vulnerability can be trigg
debian
CVE-2014-1947P3LOWCVSS 7.8PoCfixed in graphicsmagick 1.3.20-1 (bookworm)2014
CVE-2014-1947 [HIGH] CVE-2014-1947: graphicsmagick - Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in Ima...
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.
Scope: local
bookworm: resolved (fixed
debian
CVE-2016-5239P2CRITICALCVSS 9.8fixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-5239 [CRITICAL] CVE-2016-5239: graphicsmagick - The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMag...
The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3.24-1
debian
CVE-2017-14103P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-8 (bookworm)2017
CVE-2017-14103 [HIGH] CVE-2017-14103: graphicsmagick - The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick...
The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote attackers to conduct use-after-free attacks via a crafted file, related to a ReadMNGImage out-of-order CloseBlob call. NOTE: this vulnerability exists because of an incomplete fix for
debian
CVE-2017-11403P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-3 (bookworm)2017
CVE-2017-11403 [HIGH] CVE-2017-11403: graphicsmagick - The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of...
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.26-3)
bullseye: resolved (fixed in 1.3.26-3)
forky: resolved (fixed in 1.3.26-3)
sid: resolved (fixed in 1.3.26-3)
trixie: resolved (fixed in 1.3.26-3)
debian
CVE-2016-3716P3LOWCVSS 3.3PoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3716 [LOW] CVE-2016-3716: graphicsmagick - The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remot...
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3.24-1)
debian
CVE-2017-12936P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-6 (bookworm)2017
CVE-2017-12936 [HIGH] CVE-2017-12936: graphicsmagick - The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-aft...
The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.
Scope: local
bookworm: resolved (fixed in 1.3.26-6)
bullseye: resolved (fixed in 1.3.26-6)
forky: resolved (fixed in 1.3.26-6)
sid: resolved (fixed in 1.3.26-6)
trixie: resolved (fixed in 1.3.26-6)
debian
CVE-2016-7996P3CRITICALCVSS 9.8fixed in graphicsmagick 1.3.21-2 (bookworm)2016
CVE-2016-7996 [CRITICAL] CVE-2016-7996: graphicsmagick - Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and...
Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.
Scope: local
bookworm: resolved (fixed in 1.3.21-2)
bullseye: resolved (fixed in 1.3.21-2)
forky: resolved (fixed in 1.3.21-2)
sid: resolved (fixed in 1.3.21-2)
trixie: res
debian
CVE-2016-7446P3MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.25-1 (bookworm)2016
CVE-2016-7446 [MEDIUM] CVE-2016-7446: graphicsmagick - Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allow...
Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete patch for CVE-2016-2317.
Scope: local
bookworm: resolved (fixed in 1.3.25-1)
bullseye: resolved (fixed in 1.3.25-1)
forky: resolved (fixed in 1.3.25-1)
sid: reso
debian
CVE-2020-10938P3CRITICALCVSS 9.8fixed in graphicsmagick 1.4+really1.3.34-1 (bookworm)2020
CVE-2020-10938 [CRITICAL] CVE-2020-10938: graphicsmagick - GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based bu...
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.34-1)
bullseye: resolved (fixed in 1.4+really1.3.34-1)
forky: resolved (fixed in 1.4+really1.3.34-1)
sid: resolved (fixed in 1.4+really1.3.34-1)
trixie: resolved (
debian
CVE-2016-7447P3CRITICALCVSS 9.8fixed in graphicsmagick 1.3.25-1 (bookworm)2016
CVE-2016-7447 [CRITICAL] CVE-2016-7447: graphicsmagick - Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick b...
Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.3.25-1)
bullseye: resolved (fixed in 1.3.25-1)
forky: resolved (fixed in 1.3.25-1)
sid: resolved (fixed in 1.3.25-1)
trixie: resolved (fixed in 1.3.25
debian
CVE-2006-4144P4MEDIUMCVSS 2.6PoCfixed in graphicsmagick 1.1.7-7 (bookworm)2006
CVE-2006-4144 [LOW] CVE-2006-4144: graphicsmagick - Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2...
Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.1.7-7)
bullseye: resolve
debian
CVE-2025-27796P3LOWCVSS 4.5fixed in graphicsmagick 1.4+really1.3.45+hg17689-1 (forky)2025
CVE-2025-27796 [MEDIUM] CVE-2025-27796: graphicsmagick - ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer al...
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.4+really1.3.45+hg17689-1)
sid: resolved (fixed in 1.4+really1.3.45+hg17689-1)
trixie: resolved (fixed in 1.4+really1.3.45+hg1768
debian
CVE-2017-11636P3CRITICALCVSS 9.8fixed in graphicsmagick 1.3.26-4 (bookworm)2017
CVE-2017-11636 [CRITICAL] CVE-2017-11636: graphicsmagick - GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in cod...
GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widths.
Scope: local
bookworm: resolved (fixed in 1.3.26-4)
bullseye: resolved (fixed in 1.3.26-4)
forky: resolved (fixed in 1.3.26-4)
sid: resolved (fixed in 1.3.26-4)
trixie: resolved (fixed in 1.3.26-4)
debian
1 / 8Next →