Search CVE reports


Toggle filters

1 – 10 of 142 results


CVE-2025-32460

Medium priority
Needs evaluation

GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-27796

Medium priority
Fixed

ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-27795

Medium priority
Fixed

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Fixed Fixed Not affected Not affected
Show less packages

CVE-2022-1270

Medium priority
Fixed

In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Fixed Fixed
Show less packages

CVE-2020-21679

Medium priority
Ignored

Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected Ignored
Show less packages

CVE-2020-15999

High priority

Some fixes available 16 of 17

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

18 affected packages

chromium-browser, godot, graphicsmagick, musescore, openjdk-13...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not affected Not in release Fixed
godot Not affected Not affected Not affected Not in release
graphicsmagick Not affected Not affected Not affected Not affected
musescore Not in release Not in release Not affected Not affected
openjdk-13 Not in release Not in release Not affected Not in release
texmaker Not affected Not affected Not affected Not affected
android Not in release Not in release Not in release Not in release
firefox Not affected Not affected Not in release Not affected
freetype Fixed Fixed Fixed Fixed
openjdk-lts Not affected Not affected Not affected Not affected
openjdk-15 Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release
paraview Not affected Not affected Not affected Not affected
qtbase-opensource-src Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not in release Not affected
openjdk-12 Not in release Not in release Not in release Not in release
qtbase-opensource-src-gles Not affected Not affected Not affected Not in release
texlive-bin Not affected Not affected Not affected Not affected
Show all 18 packages Show less packages

CVE-2020-12672

Medium priority

Some fixes available 4 of 5

GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Fixed Fixed
Show less packages

CVE-2020-10938

Medium priority

Some fixes available 3 of 4

GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Fixed
Show less packages

CVE-2019-2224

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15140. Reason: This candidate is a duplicate of CVE-2019-15140. Notes: All CVE users should reference CVE-2019-15140 instead of this candidate. All references...

2 affected packages

graphicsmagick, imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
imagemagick Not affected
Show less packages

CVE-2019-19953

Medium priority

Some fixes available 3 of 5

In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Fixed
Show less packages