Debian Graphicsmagick vulnerabilities
141 known vulnerabilities affecting debian/graphicsmagick.
Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH47MEDIUM56LOW21
Vulnerabilities
Page 6 of 8
CVE-2006-3743P4MEDIUMCVSS 5.1fixed in graphicsmagick 1.1.7-8 (bookworm)2006
CVE-2006-3743 [MEDIUM] CVE-2006-3743: graphicsmagick - Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attack...
Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.
Scope: local
bookworm: resolved (fixed in 1.1.7-8)
bullseye: resolved (fixed in 1.1.7-8)
forky: resolved (fixed in 1.1.7-8)
sid: resolved (fixed in 1.1.7-8)
trixie: resolved (fixed in 1.1.7-8)
debian
CVE-2018-9018P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.28-2 (bookworm)2018
CVE-2018-9018 [MEDIUM] CVE-2018-9018: graphicsmagick - In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function...
In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.
Scope: local
bookworm: resolved (fixed in 1.3.28-2)
bullseye: resolved (fixed in 1.3.28-2)
forky: resolved (fixed in 1.3.28-2)
sid: resolved (fixed i
debian
CVE-2019-11473P4HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15976-1 (bookworm)2019
CVE-2019-11473 [HIGH] CVE-2019-11473: graphicsmagick - coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of serv...
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
Scope: local
bookworm: resolved (fixed in 1.4~hg15976-1)
bullseye: resolved (fixed in 1.4~hg15976-1)
forky: resolved (fixed in 1.4~hg1597
debian
CVE-2019-11474P4HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15976-1 (bookworm)2019
CVE-2019-11474 [HIGH] CVE-2019-11474: graphicsmagick - coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of serv...
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
Scope: local
bookworm: resolved (fixed in 1.4~hg15976-1)
bullseye: resolved (fixed in 1.4~hg15976-1)
forky: resolved (fixed in 1.4~
debian
CVE-2006-3744P4MEDIUMCVSS 5.1fixed in graphicsmagick 1.1.7-7 (bookworm)2006
CVE-2006-3744 [MEDIUM] CVE-2006-3744: graphicsmagick - Multiple integer overflows in ImageMagick before 6.2.9 allows user-assisted atta...
Multiple integer overflows in ImageMagick before 6.2.9 allows user-assisted attackers to execute arbitrary code via crafted Sun Rasterfile (bitmap) images that trigger heap-based buffer overflows.
Scope: local
bookworm: resolved (fixed in 1.1.7-7)
bullseye: resolved (fixed in 1.1.7-7)
forky: resolved (fixed in 1.1.7-7)
sid: resolved (fixed in 1.1.7-7)
trixie:
debian
CVE-2017-14504P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-11 (bookworm)2017
CVE-2017-14504 [MEDIUM] CVE-2017-14504: graphicsmagick - ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correc...
ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors for the XV 332 format, leading to a NULL Pointer Dereference.
Scope: local
bookworm: resolved (fixed in 1.3.26-11)
bullseye: resolved (fixed in 1.3.26-11)
forky: resolved (fixed in 1.3.26-11)
sid: resolved (fixed in 1.3.26-11)
trixie: resolved (fixed in 1.3.26
debian
CVE-2017-14733P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-13 (bookworm)2017
CVE-2017-14733 [MEDIUM] CVE-2017-14733: graphicsmagick - ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers tha...
ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.26-13)
bullseye: resolved (fixed in 1.3.26-13)
forky: resolved (fixed in 1.3
debian
CVE-2017-13134P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-19 (bookworm)2017
CVE-2017-13134 [MEDIUM] CVE-2017-13134: graphicsmagick - In ImageMagick 7.0.6-6 and GraphicsMagick 1.3.26, a heap-based buffer over-read ...
In ImageMagick 7.0.6-6 and GraphicsMagick 1.3.26, a heap-based buffer over-read was found in the function SFWScan in coders/sfw.c, which allows attackers to cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.26-19)
bullseye: resolved (fixed in 1.3.26-19)
forky: resolved (fixed in 1.3.26-19)
sid: resolved (fixed in 1.
debian
CVE-2018-5685P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.27-4 (bookworm)2018
CVE-2018-5685 [MEDIUM] CVE-2018-5685: graphicsmagick - In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ...
In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with a crafted bit-field mask value.
Scope: local
bookworm: resolved (fixed in 1.3.27-4)
bullseye: resolved (fixed in 1.3.27-4)
forky: resolved (
debian
CVE-2017-13065P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-7 (bookworm)2017
CVE-2017-13065 [MEDIUM] CVE-2017-13065: graphicsmagick - GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the functi...
GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.
Scope: local
bookworm: resolved (fixed in 1.3.26-7)
bullseye: resolved (fixed in 1.3.26-7)
forky: resolved (fixed in 1.3.26-7)
sid: resolved (fixed in 1.3.26-7)
trixie: resolved (fixed in 1.3.26-7)
debian
CVE-2017-14314P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-10 (bookworm)2017
CVE-2017-14314 [MEDIUM] CVE-2017-14314: graphicsmagick - Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick ...
Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDashPolygon heap-based buffer over-read and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.26-10)
bullseye: resolved (fixed in 1.3.26-10)
forky: resolved (fixed in 1.3.26-10)
s
debian
CVE-2017-11722P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-4 (bookworm)2017
CVE-2017-11722 [MEDIUM] CVE-2017-11722: graphicsmagick - The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows re...
The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its indentation. This resulted in a logging statement executing outside of a loop, and consequently using an
debian
CVE-2017-18230P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-18230 [MEDIUM] CVE-2017-18230: graphicsmagick - An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vul...
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
bullseye: resolved (fixed in 1.3.27-1)
forky: resolved (fixed in 1.3.27-1)
sid: re
debian
CVE-2017-18231P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-18231 [MEDIUM] CVE-2017-18231: graphicsmagick - An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vul...
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadEnhMetaFile in coders/emf.c, which allows attackers to cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
bullseye: resolved (fixed in 1.3.27-1)
forky: resolved (fixed in 1.3.27-1)
sid: resol
debian
CVE-2006-5456P4MEDIUMCVSS 5.1fixed in graphicsmagick 1.1.7-9 (bookworm)2006
CVE-2006-5456 [MEDIUM] CVE-2006-5456: graphicsmagick - Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 a...
Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/pal
debian
CVE-2019-16709P4LOWCVSS 6.5fixed in graphicsmagick 1.4+really1.3.33+hg16117-1 (bookworm)2019
CVE-2019-16709 [MEDIUM] CVE-2019-16709: graphicsmagick - ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCrea...
ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.33+hg16117-1)
bullseye: resolved (fixed in 1.4+really1.3.33+hg16117-1)
forky: resolved (fixed in 1.4+really1.3.33+hg16117-1)
sid: resolved (fixed in 1.4+really1.3.33+hg16117-1)
trixie: resolved (fixed in 1.4+really
debian
CVE-2018-18544P4LOWCVSS 6.5fixed in graphicsmagick 1.3.31-1 (bookworm)2018
CVE-2018-18544 [MEDIUM] CVE-2018-18544: graphicsmagick - There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMag...
There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.
Scope: local
bookworm: resolved (fixed in 1.3.31-1)
bullseye: resolved (fixed in 1.3.31-1)
forky: resolved (fixed in 1.3.31-1)
sid: resolved (fixed in 1.3.31-1)
trixie: resolved
debian
CVE-2019-11010P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11010 [MEDIUM] CVE-2019-11010: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the functi...
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
Scope: local
bookworm: resolved (fixed in 1.4~hg15968-1)
bullseye: resolved (fixed in 1.4~hg15968-1)
forky: resolved (fixed in 1.4~hg15968-1)
sid: resolved (fixed in 1.
debian
CVE-2017-13066P4LOWCVSS 6.5fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-13066 [MEDIUM] CVE-2017-13066: graphicsmagick - GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage...
GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage in magick/image.c.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
bullseye: resolved (fixed in 1.3.27-1)
forky: resolved (fixed in 1.3.27-1)
sid: resolved (fixed in 1.3.27-1)
trixie: resolved (fixed in 1.3.27-1)
debian
CVE-2017-13648P4LOWCVSS 6.5fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-13648 [MEDIUM] CVE-2017-13648: graphicsmagick - In GraphicsMagick 1.3.26, a memory leak vulnerability was found in the function ...
In GraphicsMagick 1.3.26, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
bullseye: resolved (fixed in 1.3.27-1)
forky: resolved (fixed in 1.3.27-1)
sid: resolved (fixed in 1.3.27-1)
trixie: resolved (fixed in 1.3.27-1)
debian