Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.29% | — | GraphicsmagickAI | 30/9/2026 | 2/10/2026 | A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2.… | |
| Aplazada | Alta (8.4) | 0.17% | — | GraphicsmagickAI | 20/8/2026 | 9/9/2026 | A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against the end of the heap-allocated luma/chroma plane buffers. The pointer is repositioned only… | |
| Analizada | Crítica (9.1) | 0.35% | — | Graphicsmagick | 9/4/2025 | 17/6/2026 | GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call. | |
| Analizada | Crítica (9.8) | 0.39% | — | Graphicsmagick | 7/3/2025 | 17/6/2026 | ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob. | |
| Analizada | Alta (7.5) | 0.45% | — | Graphicsmagick | 7/3/2025 | 17/6/2026 | ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. | |
| Modificada | Media (5.5) | 0.43% | — | Graphicsmagick | 22/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format. | |
| Modificada | Alta (7.8) | 0.46% | — | GraphicsmagickDebian Linux | 28/9/2022 | 17/6/2026 | In GraphicsMagick, a heap buffer overflow was found when parsing MIFF. | |
| Modificada | Alta (7.5) | 2.9% | — | GraphicsmagickDebian LinuxOpensuse Backports SLEOpensuse Leap | 6/5/2020 | 17/6/2026 | GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c. | |
| Modificada | Crítica (9.8) | 5.4% | — | GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap | 24/3/2020 | 17/6/2026 | GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c. | |
| Modificada | Media (6.5) | 8.0% | — | GraphicsmagickDebian LinuxOpensuse Backports SLEOpensuse Leap | 18/3/2020 | 17/6/2026 | In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG. | |
| Modificada | Crítica (9.1) | 2.8% | — | GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap | 24/12/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c. | |
| Modificada | Crítica (9.8) | 2.5% | — | GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap | 24/12/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c. | |
| Modificada | Crítica (9.8) | 2.7% | — | GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap | 24/12/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c. | |
| Modificada | Alta (8.8) | 2.6% | — | GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 24/4/2019 | 17/6/2026 | In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in… | |
| Modificada | Alta (8.8) | 2.9% | — | GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 24/4/2019 | 17/6/2026 | In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in… | |
| Modificada | Media (6.5) | 2.2% | — | GraphicsmagickFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+2 | 23/4/2019 | 17/6/2026 | coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009. | |
| Modificada | Media (6.5) | 2.4% | — | Graphicsmagick | 23/4/2019 | 17/6/2026 | coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009. | |
| Modificada | Media (6.5) | 1.8% | — | GraphicsmagickDebian LinuxOpensuse Leap | 8/4/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file. | |
| Modificada | Alta (8.1) | 2.4% | — | GraphicsmagickOpensuse LeapDebian Linux | 8/4/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file. | |
| Modificada | Alta (8.8) | 3.8% | — | GraphicsmagickOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 8/4/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file. | |
| Modificada | Alta (8.1) | 2.0% | — | GraphicsmagickOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 8/4/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap. | |
| Modificada | Crítica (9.1) | 2.9% | — | GraphicsmagickOpensuse LeapDebian Linux | 8/4/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet. | |
| Modificada | Crítica (9.8) | 3.5% | — | GraphicsmagickOpensuse Leap | 8/4/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value. | |
| Modificada | Alta (7.5) | 3.8% | — | ImagemagickGraphicsmagickOpensuse LeapDebian Linux+1 | 5/2/2019 | 17/6/2026 | In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c. | |
| Modificada | Media (6.5) | 2.3% | — | GraphicsmagickDebian Linux | 17/12/2018 | 17/6/2026 | In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization. |