Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.5% | — | GraphicsmagickDebian LinuxOpensuse LeapOpensuse | 6/2/2017 | 17/6/2026 | The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a file containing an "unterminated" string. | |
| Modificada | Alta (7.5) | 3.8% | — | GraphicsmagickDebian LinuxOpensuse LeapOpensuse | 6/2/2017 | 17/6/2026 | The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size. | |
| Modificada | Crítica (9.8) | 4.0% | — | GraphicsmagickDebian LinuxOpensuse LeapOpensuse | 6/2/2017 | 17/6/2026 | Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors. | |
| Modificada | Crítica (9.8) | 4.0% | — | GraphicsmagickDebian LinuxOpensuse LeapOpensuse | 6/2/2017 | 17/6/2026 | Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete patch for CVE-2016-2317. | |
| Modificada | Media (5.5) | 1.6% | — | GraphicsmagickDebian LinuxOpensuse LeapOpensuse | 3/2/2017 | 17/6/2026 | magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file. | |
| Modificada | Media (5.5) | 1.9% | — | GraphicsmagickDebian LinuxSuse Linux Enterprise DebuginfoSuse Studio Onsite+3 | 3/2/2017 | 17/6/2026 | GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c. | |
| Modificada | Media (5.5) | 2.0% | — | GraphicsmagickDebian LinuxSuse Linux Enterprise DebuginfoSuse Studio Onsite+3 | 3/2/2017 | 17/6/2026 | Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c. | |
| Modificada | Alta (7.5) | 3.4% | — | Graphicsmagick | 18/1/2017 | 17/6/2026 | The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer. | |
| Modificada | Crítica (9.8) | 3.9% | — | Graphicsmagick | 18/1/2017 | 17/6/2026 | Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries. | |
| Modificada | Media (5.5) | 1.5% | — | GraphicsmagickSuse Linux Enterprise DebuginfoSuse Studio OnsiteSuse Linux Enterprise Software Development KIT+1 | 13/7/2016 | 17/6/2026 | The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file. | |
| Modificada | Crítica (9.8) | 50% | — | GraphicsmagickSuse Linux Enterprise DebuginfoSuse Studio OnsiteSuse Linux Enterprise Software Development KIT+10 | 10/6/2016 | 17/6/2026 | The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename. | |
| Modificada | Media (4.3) | 2.3% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Studio OnsiteNovell Suse Linux Enterprise DebuginfoGraphicsmagick+1 | 23/11/2013 | 16/6/2026 | The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image. | |
| Modificada | Media (4.3) | 2.5% | — | Graphicsmagick | 7/8/2012 | 16/6/2026 | The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation. | |
| Modificada | Alta (7.8) | 3.0% | — | Graphicsmagick | 6/4/2009 | 16/6/2026 | Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 2.6% | — | Graphicsmagick | 10/2/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allow remote attackers to cause a denial of service (crash) via unspecified vectors in (1) XCF and (2) CINEON images. | |
| Modificada | Alta (10) | 6.7% | — | Graphicsmagick | 10/2/2009 | 16/6/2026 | Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PICT image. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (9.3) | 4.0% | — | Graphicsmagick | 10/2/2009 | 16/6/2026 | Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PALM image, a different vulnerability than CVE-2007-0770. NOTE: some of these details are… | |
| Modificada | Media (5) | 2.1% | — | Graphicsmagick | 10/7/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the… | |
| Modificada | Media (6.8) | 4.5% | — | Imagemagick GraphicsmagickImagemagick | 5/3/2008 | 16/6/2026 | The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to… | |
| Modificada | Media (6.8) | 4.5% | — | Imagemagick GraphicsmagickImagemagick | 5/3/2008 | 16/6/2026 | Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers… | |
| Modificada | Alta (9.3) | 5.4% | — | GraphicsmagickImagemagick | 12/2/2007 | 16/6/2026 | Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456. | |
| Modificada | Media (5.1) | 3.8% | — | GraphicsmagickImagemagick | 23/10/2006 | 16/6/2026 | Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled… | |
| Modificada | Media (5) | 4.2% | — | GraphicsmagickImagemagick | 24/5/2005 | 16/6/2026 | The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask. | |
| Modificada | Alta (7.5) | 4.4% | — | GraphicsmagickImagemagickSGI PropackDebian Linux+2 | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers. | |
| Modificada | Media (5) | 14% | 💥 Exploit | GraphicsmagickImagemagick | 25/4/2005 | 16/6/2026 | Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value. |