Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 2.1% | — | GraphicsmagickDebian LinuxCanonical Ubuntu Linux | 17/12/2018 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects GraphicsMagick installations with customized BMP limits. | |
| Modificada | Media (6.5) | 2.3% | — | GraphicsmagickDebian Linux | 17/12/2018 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification. | |
| Modificada | Media (6.5) | 2.0% | — | GraphicsmagickImagemagickOpensuse Leap | 21/10/2018 | 17/6/2026 | There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31. | |
| Modificada | Media (6.5) | 3.0% | — | GraphicsmagickDebian Linux | 25/3/2018 | 17/6/2026 | In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file. | |
| Modificada | Media (6.5) | 1.7% | — | GraphicsmagickDebian Linux | 14/3/2018 | 17/6/2026 | An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadEnhMetaFile in coders/emf.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (6.5) | 1.7% | — | GraphicsmagickDebian Linux | 14/3/2018 | 17/6/2026 | An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (6.5) | 2.3% | — | GraphicsmagickDebian Linux | 14/3/2018 | 17/6/2026 | An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations. | |
| Modificada | Alta (8.8) | 3.6% | — | Graphicsmagick | 5/3/2018 | 17/6/2026 | The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c CloseBlob use-after-free) or possibly have unspecified other impact via a crafted file, a related issue to CVE-2017-11403. | |
| Modificada | Media (6.5) | 3.3% | — | GraphicsmagickDebian Linux | 5/3/2018 | 17/6/2026 | An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted file that triggers an attempt at a large png_pixels array allocation. | |
| Modificada | Alta (8.8) | 2.5% | — | GraphicsmagickDebian Linux | 7/2/2018 | 17/6/2026 | The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used. | |
| Modificada | Media (6.5) | 1.9% | — | GraphicsmagickDebian Linux | 14/1/2018 | 17/6/2026 | In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with a crafted bit-field mask value. | |
| Modificada | Alta (8.8) | 1.8% | — | LibtiffGraphicsmagick | 14/1/2018 | 17/6/2026 | LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27. | |
| Modificada | Alta (8.8) | 1.8% | — | GraphicsmagickDebian Linux | 27/12/2017 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached. | |
| Modificada | Alta (8.8) | 1.6% | — | GraphicsmagickDebian Linux | 27/12/2017 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type. | |
| Modificada | Alta (8.8) | 1.8% | — | GraphicsmagickDebian Linux | 27/12/2017 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region. | |
| Modificada | Alta (7.5) | 1.5% | — | GraphicsmagickDebian Linux | 20/12/2017 | 17/6/2026 | In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8. | |
| Modificada | Alta (8.8) | 1.8% | — | GraphicsmagickDebian Linux | 20/12/2017 | 17/6/2026 | In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation. | |
| Modificada | Alta (8.8) | 1.9% | — | GraphicsmagickDebian Linux | 11/12/2017 | 17/6/2026 | ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file. | |
| Modificada | Alta (8.8) | 1.9% | — | GraphicsmagickDebian Linux | 11/12/2017 | 17/6/2026 | ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file. | |
| Modificada | Alta (8.8) | 2.6% | — | GraphicsmagickDebian Linux | 11/12/2017 | 17/6/2026 | WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file. | |
| Modificada | Alta (8.8) | 2.6% | — | GraphicsmagickDebian Linux | 11/12/2017 | 17/6/2026 | ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file. | |
| Modificada | Alta (8.8) | 2.9% | — | Graphicsmagick | 11/12/2017 | 17/6/2026 | WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBitStreamMSBWrite heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Alta (8.8) | 3.4% | — | GraphicsmagickDebian Linux | 9/11/2017 | 17/6/2026 | coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c. | |
| Modificada | Alta (8.8) | 2.3% | — | Graphicsmagick | 6/11/2017 | 17/6/2026 | The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Alta (8.8) | 2.2% | — | Graphicsmagick | 5/11/2017 | 17/6/2026 | The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType invalid write and application crash) or possibly have unspecified other impact via a malformed WPG image. |