Search CVE reports


Toggle filters

21 – 30 of 142 results


CVE-2019-11007

Medium priority

Some fixes available 1 of 5

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-11006

Medium priority

Some fixes available 3 of 5

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Fixed
Show less packages

CVE-2019-11005

Medium priority

Some fixes available 1 of 3

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Fixed
Show less packages

CVE-2018-9018

Medium priority

Some fixes available 3 of 4

In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Fixed
Show less packages

CVE-2018-6799

Medium priority
Vulnerable

The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file,...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-5685

Medium priority

Some fixes available 2 of 3

In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with a crafted...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected
Show less packages

CVE-2018-20189

Medium priority

Some fixes available 3 of 4

In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Fixed
Show less packages

CVE-2018-20185

Medium priority

Some fixes available 1 of 4

In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-20184

Medium priority

Some fixes available 3 of 4

In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Fixed
Show less packages

CVE-2017-6887

Low priority

Some fixes available 3 of 113

A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100"...

12 affected packages

dcraw, darktable, exactimage, kodi, rawtherapee...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Vulnerable Vulnerable Vulnerable Vulnerable
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Vulnerable
flphoto Not in release Not in release Not in release Not in release
freeimage Not affected Not affected Not affected Not affected
graphicsmagick Not affected Not affected Not affected Not affected
rawstudio Not in release Not in release Not in release Not in release
xbmc Not in release Not in release Not in release Not in release
Show all 12 packages Show less packages