Debian Libwmf vulnerabilities
11 known vulnerabilities affecting debian/libwmf.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM8LOW3
Vulnerabilities
Page 1 of 1
CVE-2016-9011MEDIUMCVSS 5.5fixed in libwmf 0.2.8.4-10.6 (bookworm)2016
CVE-2016-9011 [MEDIUM] CVE-2016-9011: libwmf - The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to ca...
The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (application crash) via a crafted wmf file, which triggers a memory allocation failure.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-10.6)
bullseye: resolved (fixed in 0.2.8.4-10.6)
forky: resolved (fixed in 0.2.8.4-10.6)
sid: resolved (fixed in 0.2.8.4-10.6)
debian
CVE-2015-4696MEDIUMCVSS 4.3fixed in libwmf 0.2.8.4-10.4 (bookworm)2015
CVE-2015-4696 [MEDIUM] CVE-2015-4696: libwmf - Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause ...
Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-10.4)
bullseye: resolved (fixed in 0.2.8.4-10.4)
forky: resolved (fixed in 0.2.8.4-10.4)
sid: resolved (fixed in 0.2.8.4-10.4)
trixie: resolved (f
debian
CVE-2015-0848MEDIUMCVSS 6.8fixed in libwmf 0.2.8.4-10.4 (bookworm)2015
CVE-2015-0848 [MEDIUM] CVE-2015-0848: libwmf - Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a ...
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-10.4)
bullseye: resolved (fixed in 0.2.8.4-10.4)
forky: resolved (fixed in 0.2.8.4-10.4)
sid: resolved (fixed in 0.2.8.4-10.4)
trixie: resolved (fixed in
debian
CVE-2015-4695MEDIUMCVSS 5.0fixed in libwmf 0.2.8.4-10.4 (bookworm)2015
CVE-2015-4695 [MEDIUM] CVE-2015-4695: libwmf - meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (o...
meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-10.4)
bullseye: resolved (fixed in 0.2.8.4-10.4)
forky: resolved (fixed in 0.2.8.4-10.4)
sid: resolved (fixed in 0.2.8.4-10.4)
trixie: resolved (fixed in 0.2.8.4-10.4)
debian
CVE-2015-4588MEDIUMCVSS 6.8fixed in libwmf 0.2.8.4-10.4 (bookworm)2015
CVE-2015-4588 [MEDIUM] CVE-2015-4588: libwmf - Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows ...
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-10.4)
bullseye: resolved (fixed in 0.2.8.4-10.4)
forky: resolved (fixed in 0.2.8.4-10.4)
s
debian
CVE-2009-3546MEDIUMCVSS 7.5fixed in libgd2 2.0.36~rc1~dfsg-3.1 (bookworm)2009
CVE-2009-3546 [HIGH] CVE-2009-3546: libgd2 - The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and t...
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtaine
debian
CVE-2009-1364LOWCVSS 7.5fixed in libwmf 0.2.8.4-6.1 (bookworm)2009
CVE-2009-1364 [HIGH] CVE-2009-1364: libwmf - Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows...
Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-6.1)
bullseye: resolved (fixed in 0.2.8.4-6.1)
forky: resolved (fixed in 0.2.8.4-6.1)
sid: resolved (fix
debian
CVE-2007-3996MEDIUMCVSS 6.8fixed in libgd2 2.0.35.dfsg-1 (bookworm)2007
CVE-2007-3996 [MEDIUM] CVE-2007-3996: libgd2 - Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers t...
Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.
Scope:
debian
CVE-2007-3476LOWCVSS 4.3fixed in libgd2 2.0.35.dfsg-1 (bookworm)2007
CVE-2007-3476 [MEDIUM] CVE-2007-3476: libgd2 - Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.3...
Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.
Scope: local
bookworm: resolved (fixed in 2.0.35.dfsg-1)
bullseye: resolved (fixed in 2.0.35.dfsg-1)
debian
CVE-2007-3477LOWCVSS 5.0fixed in libgd2 2.0.35.dfsg-1 (bookworm)2007
CVE-2007-3477 [MEDIUM] CVE-2007-3477: libgd2 - The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd)...
The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value.
Scope: local
bookworm: resolved (fixed in 2.0.35.dfsg-1)
bullseye: resolved (fixed in 2.0.35.dfsg-1)
forky: resolved (fixed in 2.0.35.dfsg-1)
sid: resolved (f
debian
CVE-2006-3376MEDIUMCVSS 7.5fixed in libwmf 0.2.8.4-2 (bookworm)2006
CVE-2006-3376 [HIGH] CVE-2006-3376: libwmf - Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products inc...
Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a WMF file.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-2)
bullseye: resolved (fixed in 0.2.8.4-2)
forky: resolve
debian