Debian Graphicsmagick vulnerabilities
142 known vulnerabilities affecting debian/graphicsmagick.
Total CVEs
142
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH47MEDIUM56LOW22
Vulnerabilities
Page 1 of 8
CVE-2025-27795MEDIUMCVSS 4.3fixed in graphicsmagick 1.4+really1.3.40-4+deb12u1 (bookworm)2025
CVE-2025-27795 [MEDIUM] CVE-2025-27795: graphicsmagick - ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resour...
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.40-4+deb12u1)
bullseye: resolved
forky: resolved (fixed in 1.4+really1.3.45+hg17689-1)
sid: resolved (fixed in 1.4+really1.3.45+hg17689-1)
trixie: resolved (fixed in 1.4+really1.3.45+hg17689-1)
debian
CVE-2025-32460MEDIUMCVSS 4.0fixed in graphicsmagick 1.4+really1.3.40-4+deb12u1 (bookworm)2025
CVE-2025-32460 [MEDIUM] CVE-2025-32460: graphicsmagick - GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage ...
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.40-4+deb12u1)
bullseye: resolved
forky: resolved (fixed in 1.4+really1.3.45+hg17696-1)
sid: resolved (fixed in 1.4+really1.3.45+hg17696-1)
trixie: resolved (fixed in
debian
CVE-2025-27796LOWCVSS 4.5fixed in graphicsmagick 1.4+really1.3.45+hg17689-1 (forky)2025
CVE-2025-27796 [MEDIUM] CVE-2025-27796: graphicsmagick - ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer al...
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.4+really1.3.45+hg17689-1)
sid: resolved (fixed in 1.4+really1.3.45+hg17689-1)
trixie: resolved (fixed in 1.4+really1.3.45+hg1768
debian
CVE-2022-1270HIGHCVSS 7.8fixed in graphicsmagick 1.4+really1.3.38-1 (bookworm)2022
CVE-2022-1270 [HIGH] CVE-2022-1270: graphicsmagick - In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.38-1)
bullseye: resolved (fixed in 1.4+really1.3.36+hg16481-2+deb11u1)
forky: resolved (fixed in 1.4+really1.3.38-1)
sid: resolved (fixed in 1.4+really1.3.38-1)
trixie: resolved (fixed in 1.4+really1.3.38-1)
debian
CVE-2020-10938CRITICALCVSS 9.8fixed in graphicsmagick 1.4+really1.3.34-1 (bookworm)2020
CVE-2020-10938 [CRITICAL] CVE-2020-10938: graphicsmagick - GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based bu...
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.34-1)
bullseye: resolved (fixed in 1.4+really1.3.34-1)
forky: resolved (fixed in 1.4+really1.3.34-1)
sid: resolved (fixed in 1.4+really1.3.34-1)
trixie: resolved (
debian
CVE-2020-12672HIGHCVSS 7.5fixed in graphicsmagick 1.4+really1.3.35-2 (bookworm)2020
CVE-2020-12672 [HIGH] CVE-2020-12672: graphicsmagick - GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage i...
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.35-2)
bullseye: resolved (fixed in 1.4+really1.3.35-2)
forky: resolved (fixed in 1.4+really1.3.35-2)
sid: resolved (fixed in 1.4+really1.3.35-2)
trixie: resolved (fixed in 1.4+really1.3.35-2)
debian
CVE-2020-21679MEDIUMCVSS 5.5fixed in graphicsmagick 1.4+really1.3.34+hg16181-1 (bookworm)2020
CVE-2020-21679 [MEDIUM] CVE-2020-21679: graphicsmagick - Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagi...
Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.34+hg16181-1)
bullseye: resolved (fixed in 1.4+really1.3.34+hg16181-1)
forky: resolved (fixed in 1.4+really1.3.
debian
CVE-2019-11005CRITICALCVSS 9.8fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11005 [CRITICAL] CVE-2019-11005: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overfl...
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value.
Scope: local
bookworm: resolved (fixed in 1.4~hg15968-1)
bullseye: resol
debian
CVE-2019-19950CRITICALCVSS 9.8fixed in graphicsmagick 1.4~hg16039-1 (bookworm)2019
CVE-2019-19950 [CRITICAL] CVE-2019-19950: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowEx...
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
Scope: local
bookworm: resolved (fixed in 1.4~hg16039-1)
bullseye: resolved (fixed in 1.4~hg16039-1)
forky: resolved (fixed in 1.4~hg16039-1)
sid: resolved (fixed in 1.4~hg16039-1)
trixie: resolved (fixed in 1.4~hg16039-1)
debian
CVE-2019-19953CRITICALCVSS 9.1fixed in graphicsmagick 1.4+really1.3.34-1 (bookworm)2019
CVE-2019-19953 [CRITICAL] CVE-2019-19953: graphicsmagick - In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-re...
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.34-1)
bullseye: resolved (fixed in 1.4+really1.3.34-1)
forky: resolved (fixed in 1.4+really1.3.34-1)
sid: resolved (fixed in 1.4+really1.3.34-1)
trixie: resolved (fixed in
debian
CVE-2019-11006CRITICALCVSS 9.1fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11006 [CRITICAL] CVE-2019-11006: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-re...
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet.
Scope: local
bookworm: resolved (fixed in 1.4~hg15968-1)
bullseye: resolved (fixed in 1.4~hg15968-1)
forky: resolved (fixed in 1.
debian
CVE-2019-19951CRITICALCVSS 9.8fixed in graphicsmagick 1.4~hg16039-1 (bookworm)2019
CVE-2019-19951 [CRITICAL] CVE-2019-19951: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflo...
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
Scope: local
bookworm: resolved (fixed in 1.4~hg16039-1)
bullseye: resolved (fixed in 1.4~hg16039-1)
forky: resolved (fixed in 1.4~hg16039-1)
sid: resolved (fixed in 1.4~hg16039-1)
trixie: resolved (fixed in 1.4~hg16039-1)
debian
CVE-2019-11009HIGHCVSS 8.1fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11009 [HIGH] CVE-2019-11009: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-re...
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
Scope: local
bookworm: resolved (fixed in 1.4~hg15968-1)
bullseye: resolved (fixed in 1.4~hg15968-1)
forky: resolved (fixed in 1
debian
CVE-2019-11506HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11506 [HIGH] CVE-2019-11506: graphicsmagick - In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a he...
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in magick/export.c.
Scope: local
bookworm: r
debian
CVE-2019-11505HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11505 [HIGH] CVE-2019-11505: graphicsmagick - In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a hea...
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c.
Scope: local
bookworm
debian
CVE-2019-11473HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15976-1 (bookworm)2019
CVE-2019-11473 [HIGH] CVE-2019-11473: graphicsmagick - coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of serv...
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
Scope: local
bookworm: resolved (fixed in 1.4~hg15976-1)
bullseye: resolved (fixed in 1.4~hg15976-1)
forky: resolved (fixed in 1.4~hg1597
debian
CVE-2019-11007HIGHCVSS 8.1fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11007 [HIGH] CVE-2019-11007: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-re...
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
Scope: local
bookworm: resolved (fixed in 1.4~hg15968-1)
bullseye: resolved (fixed in 1.4~hg15968-1)
forky: resolved (fixed in 1.4~
debian
CVE-2019-11008HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11008 [HIGH] CVE-2019-11008: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflo...
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
Scope: local
bookworm: resolved (fixed in 1.4~hg15968-1)
bullseye: resolved (fixed in
debian
CVE-2019-11474HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15976-1 (bookworm)2019
CVE-2019-11474 [HIGH] CVE-2019-11474: graphicsmagick - coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of serv...
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
Scope: local
bookworm: resolved (fixed in 1.4~hg15976-1)
bullseye: resolved (fixed in 1.4~hg15976-1)
forky: resolved (fixed in 1.4~
debian
CVE-2019-12921MEDIUMCVSS 6.5fixed in graphicsmagick 1.4~hg16039-1 (bookworm)2019
CVE-2019-12921 [MEDIUM] CVE-2019-12921: graphicsmagick - In GraphicsMagick before 1.3.32, the text filename component allows remote attac...
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
Scope: local
bookworm: resolved (fixed in 1.4~hg16039-1)
bullseye: resolved (fixed in 1.4~hg16039-1)
forky: resolved (fixed in 1.4~hg16039-1)
sid: resolved (fixed in 1.4~hg16039-1)
trixie: resol
debian
1 / 8Next →