Show filters
120 Total Results
Displaying 41-50 of 120
Sort by:
Attacker Value
Unknown
CVE-2017-17498
Disclosure Date: December 11, 2017 (last updated November 08, 2023)
WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBitStreamMSBWrite heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
0
Attacker Value
Unknown
CVE-2017-17502
Disclosure Date: December 11, 2017 (last updated November 08, 2023)
ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.
0
Attacker Value
Unknown
CVE-2017-16669
Disclosure Date: November 09, 2017 (last updated November 26, 2024)
coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.
0
Attacker Value
Unknown
CVE-2017-16547
Disclosure Date: November 06, 2017 (last updated November 08, 2023)
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.
0
Attacker Value
Unknown
CVE-2017-16545
Disclosure Date: November 05, 2017 (last updated November 08, 2023)
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType invalid write and application crash) or possibly have unspecified other impact via a malformed WPG image.
0
Attacker Value
Unknown
CVE-2017-16352
Disclosure Date: November 01, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magick/describe.c file. One possible way to trigger the vulnerability is to run the identify command on a specially crafted MIFF format file with the verbose flag.
0
Attacker Value
Unknown
CVE-2017-16353
Disclosure Date: November 01, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is responsible for printing the IPTC Profile information contained in the image. This vulnerability can be triggered with a specially crafted MIFF file. There is an out-of-bounds buffer dereference because certain increments are never checked.
0
Attacker Value
Unknown
CVE-2017-15930
Disclosure Date: October 27, 2017 (last updated November 08, 2023)
In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer.
0
Attacker Value
Unknown
CVE-2017-15277
Disclosure Date: October 12, 2017 (last updated November 26, 2024)
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.
0
Attacker Value
Unknown
CVE-2017-15238
Disclosure Date: October 11, 2017 (last updated November 08, 2023)
ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.
0