Search CVE reports


Toggle filters

101 – 110 of 142 results


CVE-2016-7449

Low priority

Some fixes available 2 of 3

The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a file containing an "unterminated" string.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
Show less packages

CVE-2016-7448

Low priority

Some fixes available 2 of 3

The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
Show less packages

CVE-2016-7447

Medium priority

Some fixes available 2 of 3

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
Show less packages

CVE-2016-7446

Medium priority

Some fixes available 2 of 3

Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete patch for CVE-2016-2317.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
Show less packages

CVE-2016-5241

Medium priority

Some fixes available 2 of 7

magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
Show less packages

CVE-2016-5240

Medium priority

Some fixes available 2 of 7

The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
Show less packages

CVE-2016-5239

Medium priority

Some fixes available 10 of 13

The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.

2 affected packages

imagemagick, graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Fixed
graphicsmagick Not affected
Show less packages

CVE-2016-5118

Medium priority

Some fixes available 11 of 16

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

2 affected packages

graphicsmagick, imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
imagemagick Fixed
Show less packages

CVE-2016-3718

Medium priority

Some fixes available 11 of 16

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

2 affected packages

graphicsmagick, imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
imagemagick Fixed
Show less packages

CVE-2016-3717

Medium priority

Some fixes available 11 of 16

The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

2 affected packages

graphicsmagick, imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
imagemagick Fixed
Show less packages