Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

125 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)0.29%—GraphicsmagickAI30/9/20262/10/2026
A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2.…
AplazadaAlta (8.4)0.17%—GraphicsmagickAI20/8/20269/9/2026
A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against the end of the heap-allocated luma/chroma plane buffers. The pointer is repositioned only…
AnalizadaCrítica (9.1)0.35%—Graphicsmagick9/4/202517/6/2026
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.
AnalizadaCrítica (9.8)0.39%—Graphicsmagick7/3/202517/6/2026
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
AnalizadaAlta (7.5)0.45%—Graphicsmagick7/3/202517/6/2026
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
ModificadaMedia (5.5)0.43%—Graphicsmagick22/8/202317/6/2026
Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.
ModificadaAlta (7.8)0.46%—GraphicsmagickDebian Linux28/9/202217/6/2026
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
ModificadaAlta (7.5)2.9%—GraphicsmagickDebian LinuxOpensuse Backports SLEOpensuse Leap6/5/202017/6/2026
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
ModificadaCrítica (9.8)5.4%—GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap24/3/202017/6/2026
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.
ModificadaMedia (6.5)8.0%—GraphicsmagickDebian LinuxOpensuse Backports SLEOpensuse Leap18/3/202017/6/2026
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
ModificadaCrítica (9.1)2.8%—GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap24/12/201917/6/2026
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
ModificadaCrítica (9.8)2.5%—GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap24/12/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
ModificadaCrítica (9.8)2.7%—GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap24/12/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
ModificadaAlta (8.8)2.6%—GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+124/4/201917/6/2026
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in…
ModificadaAlta (8.8)2.9%—GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+124/4/201917/6/2026
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in…
ModificadaMedia (6.5)2.2%—GraphicsmagickFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+223/4/201917/6/2026
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
ModificadaMedia (6.5)2.4%—Graphicsmagick23/4/201917/6/2026
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
ModificadaMedia (6.5)1.8%—GraphicsmagickDebian LinuxOpensuse Leap8/4/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
ModificadaAlta (8.1)2.4%—GraphicsmagickOpensuse LeapDebian Linux8/4/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
ModificadaAlta (8.8)3.8%—GraphicsmagickOpensuse Backports SLEOpensuse LeapDebian Linux+18/4/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
ModificadaAlta (8.1)2.0%—GraphicsmagickOpensuse Backports SLEOpensuse LeapDebian Linux+18/4/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
ModificadaCrítica (9.1)2.9%—GraphicsmagickOpensuse LeapDebian Linux8/4/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet.
ModificadaCrítica (9.8)3.5%—GraphicsmagickOpensuse Leap8/4/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value.
ModificadaAlta (7.5)3.8%—ImagemagickGraphicsmagickOpensuse LeapDebian Linux+15/2/201917/6/2026
In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.
ModificadaMedia (6.5)2.3%—GraphicsmagickDebian Linux17/12/201817/6/2026
In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization.