Debian Graphicsmagick vulnerabilities
141 known vulnerabilities affecting debian/graphicsmagick.
Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH47MEDIUM56LOW21
Vulnerabilities
Page 4 of 8
CVE-2016-8682P3HIGHCVSS 7.5fixed in graphicsmagick 1.3.25-5 (bookworm)2016
CVE-2016-8682 [HIGH] CVE-2016-8682: graphicsmagick - The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote...
The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted SCT header.
Scope: local
bookworm: resolved (fixed in 1.3.25-5)
bullseye: resolved (fixed in 1.3.25-5)
forky: resolved (fixed in 1.3.25-5)
sid: resolved (fixed in 1.3.25-5)
trixie: resolved (fixed in 1.3.25-5
debian
CVE-2016-8684P3HIGHCVSS 7.8fixed in graphicsmagick 1.3.25-5 (bookworm)2016
CVE-2016-8684 [HIGH] CVE-2016-8684: graphicsmagick - The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows rem...
The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure and a "file truncation error for corrupt file."
Scope: local
bookworm: resolved (fixed in 1.3.25-5)
bullseye: resolved (fixed in 1.3.25-5)
forky: resolved (fixed in 1.3.25-5)
sid
debian
CVE-2016-8683P3HIGHCVSS 7.8fixed in graphicsmagick 1.3.25-5 (bookworm)2016
CVE-2016-8683 [HIGH] CVE-2016-8683: graphicsmagick - The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote...
The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure and a "file truncation error for corrupt file."
Scope: local
bookworm: resolved (fixed in 1.3.25-5)
bullseye: resolved (fixed in 1.3.25-5)
forky: resolved (fixed in 1.3.25-5)
sid: r
debian
CVE-2017-11637P4CRITICALCVSS 9.8fixed in graphicsmagick 1.3.26-4 (bookworm)2017
CVE-2017-11637 [CRITICAL] CVE-2017-11637: graphicsmagick - GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() func...
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() function in coders/pcl.c during writes of monochrome images.
Scope: local
bookworm: resolved (fixed in 1.3.26-4)
bullseye: resolved (fixed in 1.3.26-4)
forky: resolved (fixed in 1.3.26-4)
sid: resolved (fixed in 1.3.26-4)
trixie: resolved (fixed in 1.3.26-4)
debian
CVE-2004-0981P4CRITICALCVSS 10.0fixed in graphicsmagick 1.1.7-1 (bookworm)2004
CVE-2004-0981 [CRITICAL] CVE-2004-0981: graphicsmagick - Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows r...
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
Scope: local
bookworm: resolved (fixed in 1.1.7-1)
bullseye: resolved (fixed in 1.1.7-1)
forky: resolved (fixed in 1.1.7-1)
sid: resolved (fixed in 1.1.7-1)
trixie: resolved (fixed in 1.1.7-1)
debian
CVE-2017-16547P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-18 (bookworm)2017
CVE-2017-16547 [HIGH] CVE-2017-16547: graphicsmagick - The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not prop...
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.26-18)
debian
CVE-2017-16545P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-18 (bookworm)2017
CVE-2017-16545 [HIGH] CVE-2017-16545: graphicsmagick - The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not prop...
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType invalid write and application crash) or possibly have unspecified other impact via a malformed WPG image.
Scope: local
bookworm: resolved (fixed in 1.3.26-18)
bulls
debian
CVE-2025-27795P3MEDIUMCVSS 4.3fixed in graphicsmagick 1.4+really1.3.40-4+deb12u1 (bookworm)2025
CVE-2025-27795 [MEDIUM] CVE-2025-27795: graphicsmagick - ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resour...
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.40-4+deb12u1)
bullseye: resolved
forky: resolved (fixed in 1.4+really1.3.45+hg17689-1)
sid: resolved (fixed in 1.4+really1.3.45+hg17689-1)
trixie: resolved (fixed in 1.4+really1.3.45+hg17689-1)
debian
CVE-2019-11009P4HIGHCVSS 8.1fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11009 [HIGH] CVE-2019-11009: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-re...
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
Scope: local
bookworm: resolved (fixed in 1.4~hg15968-1)
bullseye: resolved (fixed in 1.4~hg15968-1)
forky: resolved (fixed in 1
debian
CVE-2019-11007P3HIGHCVSS 8.1fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11007 [HIGH] CVE-2019-11007: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-re...
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
Scope: local
bookworm: resolved (fixed in 1.4~hg15968-1)
bullseye: resolved (fixed in 1.4~hg15968-1)
forky: resolved (fixed in 1.4~
debian
CVE-2016-7997P4HIGHCVSS 7.5fixed in graphicsmagick 1.3.25-4 (bookworm)2016
CVE-2016-7997 [HIGH] CVE-2016-7997: graphicsmagick - The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attacke...
The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer.
Scope: local
bookworm: resolved (fixed in 1.3.25-4)
bullseye: resolved (fixed in 1.3.25-4)
forky: resolved (fixed in 1.3.25-4)
sid: resolved (fixed in 1.3.25-4)
t
debian
CVE-2007-1667P4MEDIUMCVSS 9.3fixed in graphicsmagick 1.1.7-14 (bookworm)2007
CVE-2007-1667 [CRITICAL] CVE-2007-1667: graphicsmagick - Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org li...
Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.
Scope: local
bookwo
debian
CVE-2016-7448P3HIGHCVSS 7.5fixed in graphicsmagick 1.3.25-1 (bookworm)2016
CVE-2016-7448 [HIGH] CVE-2016-7448: graphicsmagick - The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to c...
The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size.
Scope: local
bookworm: resolved (fixed in 1.3.25-1)
bullseye: resolved (fixed in 1.3.25-1)
forky: resolved (fixed in 1.3.25-1)
sid: resolved (fixed
debian
CVE-2016-7449P4HIGHCVSS 7.5fixed in graphicsmagick 1.3.25-1 (bookworm)2016
CVE-2016-7449 [HIGH] CVE-2016-7449: graphicsmagick - The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remot...
The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a file containing an "unterminated" string.
Scope: local
bookworm: resolved (fixed in 1.3.25-1)
bullseye: resolved (fixed in 1.3.25-1)
forky: resolved (fixed in 1.3.25-1)
sid: resolved (fixed in 1.3.25-1)
trixie:
debian
CVE-2008-1097P4MEDIUMCVSS 6.8fixed in graphicsmagick 1.1.7-13 (bookworm)2008
CVE-2008-1097 [MEDIUM] CVE-2008-1097: graphicsmagick - Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in code...
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline ar
debian
CVE-2022-1270P4HIGHCVSS 7.8fixed in graphicsmagick 1.4+really1.3.38-1 (bookworm)2022
CVE-2022-1270 [HIGH] CVE-2022-1270: graphicsmagick - In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.38-1)
bullseye: resolved (fixed in 1.4+really1.3.36+hg16481-2+deb11u1)
forky: resolved (fixed in 1.4+really1.3.38-1)
sid: resolved (fixed in 1.4+really1.3.38-1)
trixie: resolved (fixed in 1.4+really1.3.38-1)
debian
CVE-2017-11102P4HIGHCVSS 7.5fixed in graphicsmagick 1.3.26-2 (bookworm)2017
CVE-2017-11102 [HIGH] CVE-2017-11102: graphicsmagick - The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows rem...
The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (application crash) during JNG reading via a zero-length color_image data structure.
Scope: local
bookworm: resolved (fixed in 1.3.26-2)
bullseye: resolved (fixed in 1.3.26-2)
forky: resolved (fixed in 1.3.26-2)
sid: resolved (fixed in 1.
debian
CVE-2007-1797P4MEDIUMCVSS 9.3fixed in graphicsmagick 1.1.7-15 (bookworm)2007
CVE-2007-1797 [CRITICAL] CVE-2007-1797: graphicsmagick - Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers ...
Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues t
debian
CVE-2017-11641P4CRITICALCVSS 9.8fixed in graphicsmagick 1.3.26-4 (bookworm)2017
CVE-2017-11641 [CRITICAL] CVE-2017-11641: graphicsmagick - GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/p...
GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.
Scope: local
bookworm: resolved (fixed in 1.3.26-4)
bullseye: resolved (fixed in 1.3.26-4)
forky: resolved (fixed in 1.3.26-4)
sid: resolved (fixed in 1.3.26-4)
trixie: resolved (fixed in 1.3.26-4)
debian
CVE-2007-0770P4MEDIUMCVSS 5.1fixed in graphicsmagick 1.1.7-12 (bookworm)2007
CVE-2007-0770 [MEDIUM] CVE-2007-0770: graphicsmagick - Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote at...
Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.
Scope: local
bookworm: resolved (fixed in 1.1.7-
debian