cbcvebase.

Debian Graphicsmagick vulnerabilities

141 known vulnerabilities affecting debian/graphicsmagick.

Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH47MEDIUM56LOW21

Vulnerabilities

Page 3 of 8
CVE-2020-12672P3HIGHCVSS 7.5fixed in graphicsmagick 1.4+really1.3.35-2 (bookworm)2020
CVE-2020-12672 [HIGH] CVE-2020-12672: graphicsmagick - GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage i... GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c. Scope: local bookworm: resolved (fixed in 1.4+really1.3.35-2) bullseye: resolved (fixed in 1.4+really1.3.35-2) forky: resolved (fixed in 1.4+really1.3.35-2) sid: resolved (fixed in 1.4+really1.3.35-2) trixie: resolved (fixed in 1.4+really1.3.35-2)
debian
CVE-2017-18220P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-8 (bookworm)2017
CVE-2017-18220 [HIGH] CVE-2017-18220: graphicsmagick - The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick... The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c CloseBlob use-after-free) or possibly have unspecified other impact via a crafted file, a related issue to CVE-2017-11403. Scope: local bookworm: resolved (fixed in 1.3.26-8) bullseye: resolved (fixed in 1.
debian
CVE-2019-19953P3CRITICALCVSS 9.1fixed in graphicsmagick 1.4+really1.3.34-1 (bookworm)2019
CVE-2019-19953 [CRITICAL] CVE-2019-19953: graphicsmagick - In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-re... In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c. Scope: local bookworm: resolved (fixed in 1.4+really1.3.34-1) bullseye: resolved (fixed in 1.4+really1.3.34-1) forky: resolved (fixed in 1.4+really1.3.34-1) sid: resolved (fixed in 1.4+really1.3.34-1) trixie: resolved (fixed in
debian
CVE-2017-17503P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-17503 [HIGH] CVE-2017-17503: graphicsmagick - ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c Im... ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file. Scope: local bookworm: resolved (fixed in 1.3.27-1) bullseye: resolved (fixed in 1.3.27-1) forky: resolved (fixed in 1.3.27-1) sid: resolved (fixed in 1.3.27-1) trixie: resolved (fixed in 1.3.27-1)
debian
CVE-2017-17502P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-17502 [HIGH] CVE-2017-17502: graphicsmagick - ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c Im... ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file. Scope: local bookworm: resolved (fixed in 1.3.27-1) bullseye: resolved (fixed in 1.3.27-1) forky: resolved (fixed in 1.3.27-1) sid: resolved (fixed in 1.3.27-1) trixie: resolved (fixed in 1.3.27-1)
debian
CVE-2017-11642P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-4 (bookworm)2017
CVE-2017-11642 [HIGH] CVE-2017-11642: graphicsmagick - GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() func... GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11638. Scope: local bookworm: resolved (fixed in 1.3.26-4) bullseye: resolved (fixed in 1.3.26-4) forky: resolved (fixed in 1.3.26-4) sid: resolved (fixed in 1.3.26-4) trixie: res
debian
CVE-2017-15930P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-16 (bookworm)2017
CVE-2017-15930 [HIGH] CVE-2017-15930: graphicsmagick - In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dere... In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer. Scope: local bookworm: resolved (fixed in 1.3.26-16) bullseye: resolved (fixed in 1.3.26-16) forky: resolved (fixed in 1.3.26-16) sid: resolved (fixed in 1.3.26-16) trixie: resolved (fixed in 1.3.2
debian
CVE-2017-17915P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-3 (bookworm)2017
CVE-2017-17915 [HIGH] CVE-2017-17915: graphicsmagick - In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-re... In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached. Scope: local bookworm: resolved (fixed in 1.3.27-3) bullseye: resolved (fixed in 1.3.27-3) forky: resolved (fixed in 1.3.27-3) sid: resolved (fixed in 1.3.27-3) trixi
debian
CVE-2017-17912P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-3 (bookworm)2017
CVE-2017-17912 [HIGH] CVE-2017-17912: graphicsmagick - In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-re... In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region. Scope: local bookworm: resolved (fixed in 1.3.27-3) bullseye: resolved (fixed in 1.3.27-3) forky: resolved (fixed in 1.3.27-3) sid: resolved (fixed in 1.3.27-3) trixie: res
debian
CVE-2017-11638P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-4 (bookworm)2017
CVE-2017-11638 [HIGH] CVE-2017-11638: graphicsmagick - GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() functi... GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11642. Scope: local bookworm: resolved (fixed in 1.3.26-4) bullseye: resolved (fixed in 1.3.26-4) forky: resolved (fixed in 1.3.26-4) sid: resolved (fixed in 1.3.26-4) trixie: resol
debian
CVE-2019-7397P3LOWCVSS 7.5fixed in graphicsmagick 1.4~hg15896-1 (bookworm)2019
CVE-2019-7397 [HIGH] CVE-2019-7397: graphicsmagick - In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory... In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c. Scope: local bookworm: resolved (fixed in 1.4~hg15896-1) bullseye: resolved (fixed in 1.4~hg15896-1) forky: resolved (fixed in 1.4~hg15896-1) sid: resolved (fixed in 1.4~hg15896-1) trixie: resolved (fixed in 1.4~hg15896-1)
debian
CVE-2025-32460P3MEDIUMCVSS 4.0fixed in graphicsmagick 1.4+really1.3.40-4+deb12u1 (bookworm)2025
CVE-2025-32460 [MEDIUM] CVE-2025-32460: graphicsmagick - GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage ... GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call. Scope: local bookworm: resolved (fixed in 1.4+really1.3.40-4+deb12u1) bullseye: resolved forky: resolved (fixed in 1.4+really1.3.45+hg17696-1) sid: resolved (fixed in 1.4+really1.3.45+hg17696-1) trixie: resolved (fixed in
debian
CVE-2018-6799P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.28-1 (bookworm)2018
CVE-2018-6799 [HIGH] CVE-2018-6799: graphicsmagick - The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before ... The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used. Scope: local bookworm: resolved (fixed in 1.3.28-1) bullseye: resolved (fixed in 1.3.28-1) forky
debian
CVE-2017-12937P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-6 (bookworm)2017
CVE-2017-12937 [HIGH] CVE-2017-12937: graphicsmagick - The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colorma... The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read. Scope: local bookworm: resolved (fixed in 1.3.26-6) bullseye: resolved (fixed in 1.3.26-6) forky: resolved (fixed in 1.3.26-6) sid: resolved (fixed in 1.3.26-6) trixie: resolved (fixed in 1.3.26-6)
debian
CVE-2017-12935P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-6 (bookworm)2017
CVE-2017-12935 [HIGH] CVE-2017-12935: graphicsmagick - The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles la... The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c. Scope: local bookworm: resolved (fixed in 1.3.26-6) bullseye: resolved (fixed in 1.3.26-6) forky: resolved (fixed in 1.3.26-6) sid: resolved (fixed in 1.3.26-6) trixie: resol
debian
CVE-2017-17782P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-2 (bookworm)2017
CVE-2017-17782 [HIGH] CVE-2017-17782: graphicsmagick - In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGI... In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation. Scope: local bookworm: resolved (fixed in 1.3.27-2) bullseye: resolved (fixed in 1.3.27-2) forky: resolved (fixed in 1.3.27-2) sid: resolved (fixed in 1.3.27-2) trixie: resolved (fixed in 1.3.27-2)
debian
CVE-2017-13147P3LOWCVSS 8.8fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-13147 [HIGH] CVE-2017-13147: graphicsmagick - In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the f... In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c when a small MNG file has a MEND chunk with a large length value. Scope: local bookworm: resolved (fixed in 1.3.27-1) bullseye: resolved (fixed in 1.3.27-1) forky: resolved (fixed in 1.3.27-1) sid: resolved (fixed in 1.3.27-1) trixie: resolved
debian
CVE-2016-7800P3HIGHCVSS 7.5fixed in graphicsmagick 1.3.25-3 (bookworm)2016
CVE-2016-7800 [HIGH] CVE-2016-7800: graphicsmagick - Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1... Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM chunk, which triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.3.25-3) bullseye: resolved (fixed in 1.3.25-3) forky: resolved (fixed in 1.3.
debian
CVE-2008-6070P3CRITICALCVSS 9.3fixed in graphicsmagick 1.2.3-1 (bookworm)2008
CVE-2008-6070 [CRITICAL] CVE-2008-6070: graphicsmagick - Multiple heap-based buffer underflows in the ReadPALMImage function in coders/pa... Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PALM image, a different vulnerability than CVE-2007-0770. NOTE: some of these details are obtained from third party information. Scope
debian
CVE-2017-15238P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-14 (bookworm)2017
CVE-2017-15238 [HIGH] CVE-2017-15238: graphicsmagick - ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free is... ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage. Scope: local bookworm: resolved (fixed in 1.3.26-14) bullseye: resolved (fixed in 1.3.26-14) forky: resolved (fixed in 1.3.26-14) sid: resolved (fixed in 1.3.26-14) trixie: resolved (fixed in 1.3.26-14)
debian
Debian Graphicsmagick vulnerabilities | cvebase