ZeroHour

Vulnerabilities

108 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-32460
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

NVD description · AI analysis pending
9.1<1% PoC
  • graphicsmagick graphicsmagick
CVE-2025-27796
+1 in the same advisory: …27795
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.

ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.

NVD description · AI analysis pending
9.8
group max
<1%
  • graphicsmagick graphicsmagick
CVE-2020-21679
Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of cr

Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.

NVD description · AI analysis pending
5.5<1% PoC
  • graphicsmagick graphicsmagick
CVE-2022-1270
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.

In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.

NVD description · AI analysis pending
7.8<1% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
CVE-2020-12672
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.

GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.

NVD description · AI analysis pending
7.53% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
  • graphicsmagick backports sle
  • +1 more
CVE-2020-10938
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

NVD description · AI analysis pending
9.85%
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
  • graphicsmagick backports
  • +1 more
CVE-2019-12921
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for

In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.

NVD description · AI analysis pending
6.58%
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
  • graphicsmagick backports sle
  • +1 more
CVE-2019-19950
+2 in the same advisory: …19951 …19953
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
  • graphicsmagick backports
  • +1 more
CVE-2019-11505
+1 in the same advisory: …11506
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which all

In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c.

NVD description · AI analysis pending
8.83% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
  • graphicsmagick ubuntu linux
  • +1 more
CVE-2019-11473
+1 in the same advisory: …11474
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a

coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.

NVD description · AI analysis pending
6.52%
  • graphicsmagick graphicsmagick
CVE-2019-11005
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attacker

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value.

NVD description · AI analysis pending
9.8
group max
4% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick leap
CVE-2019-7397
In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.

In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.

NVD description · AI analysis pending
7.54% PoC
  • imagemagick imagemagick
  • imagemagick graphicsmagick
  • imagemagick leap
  • +1 more
CVE-2018-20184
+2 in the same advisory: …20189 …20185
In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a deni

In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.

NVD description · AI analysis pending
6.5
group max
2% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
CVE-2018-18544
There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsM

There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.

NVD description · AI analysis pending
6.52% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick imagemagick
  • graphicsmagick leap
CVE-2018-9018
In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c.

In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.

NVD description · AI analysis pending
6.53% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
CVE-2017-18229
+2 in the same advisory: …18230 …18231
An issue was discovered in GraphicsMagick 1.3.26.

An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations.

NVD description · AI analysis pending
6.52% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
CVE-2017-18220
+1 in the same advisory: …18219
The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c Close

The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c CloseBlob use-after-free) or possibly have unspecified other impact via a crafted file, a related issue to CVE-2017-11403.

NVD description · AI analysis pending
8.8
group max
4% PoC
  • graphicsmagick graphicsmagick
CVE-2018-6799
The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or

The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.

NVD description · AI analysis pending
8.83%
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
CVE-2018-5685
In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c).

In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with a crafted bit-field mask value.

NVD description · AI analysis pending
6.52% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
CVE-2018-5360
LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in Gr

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

NVD description · AI analysis pending
8.82% PoC ×2
  • libtiff libtiff
  • libtiff graphicsmagick
CVE-2017-17915
+2 in the same advisory: …17912 …17913
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.

NVD description · AI analysis pending
8.82%
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
CVE-2017-17782
+1 in the same advisory: …17783
In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.

In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.

NVD description · AI analysis pending
8.8
group max
2%
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
CVE-2017-17498
+4 in the same advisory: …17500 …17501 …17502 …17503
WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBitStreamMSBWrite heap-based buf

WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBitStreamMSBWrite heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

NVD description · AI analysis pending
8.83%
  • graphicsmagick graphicsmagick
CVE-2017-16669
coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have u

coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.

NVD description · AI analysis pending
8.83% PoC
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux
CVE-2017-16547
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows

The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.

NVD description · AI analysis pending
8.82%
  • graphicsmagick graphicsmagick
CVE-2017-16545
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denia

The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType invalid write and application crash) or possibly have unspecified other impact via a malformed WPG image.

NVD description · AI analysis pending
8.82%
  • graphicsmagick graphicsmagick
CVE-2017-16352
+1 in the same advisory: …16353
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() f

GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magick/describe.c file. One possible way to trigger the vulnerability is to run the identify command on a specially crafted MIFF format file with the verbose flag.

NVD description · AI analysis pending
8.8
group max
15% PoC ×2
  • graphicsmagick graphicsmagick
  • graphicsmagick debian linux