Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Autotrace Project

First CVE: Dec 9, 2013Active for: 13 yearsTotal CVEs: 55
59.4
VTI Score
TOP TARGET

Autotrace Project maintains a single image-tracing utility that, despite a narrow product scope, sits among the more prominent entries in the vulnerability landscape, likely reflecting its use in document processing pipelines and embedded imaging workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in memory-safety weakness classes including out-of-bounds reads and writes, integer overflows, use-after-free conditions, and improper buffer-bounds restrictions—defects characteristic of native-code image parsers handling untrusted input. The recurrence of these low-level flaw patterns reflects Autotrace's role in parsing complex image formats with minimal overhead, creating a persistent attack surface where format-parsing logic interacts directly with memory allocation. Defenders should treat Autotrace flaws as high-priority when the utility is deployed in internet-facing or batch-processing contexts, particularly in document-conversion infrastructure where malformed images can trigger memory corruption. Current exploitation activity, KEV listing status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
55
Total CVEs
More Total CVEs than 99% of tracked vendors
13.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 84% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Autotrace Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2013
12 years ago
Most Recent CVE
Jul 14, 2022
1,475 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-9194CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:559:29.
May 23, 20179.831NONO
CVE-2017-9200CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:528:63.
May 23, 20179.830NONO
CVE-2017-9187CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:486:7.
May 23, 20179.830NONO
CVE-2017-9173CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:497:29.
May 23, 20179.830NONO
CVE-2017-9167CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:337:25.
May 23, 20179.830NONO
CVE-2017-9164CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:16:11.
May 23, 20179.830NONO
CVE-2017-9161CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in autotrace.c:188:23.
May 23, 20179.830NONO
CVE-2017-9151CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the pnm_load_ascii function in input-pnm.c:303:12.
May 23, 20179.830NONO
CVE-2017-9191CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the rle_fread function in input-tga.c:252:15.
May 23, 20179.829NONO
CVE-2017-9185CRITICAL
libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:319:7.
May 23, 20179.829NONO
View all 55 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products55 CVEs
35%
60%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (7.3%)
Network50 (90.9%)
Unknown1 (1.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (98.2%)
High0 (0.0%)
Unknown1 (1.8%)
User Interaction
None50 (90.9%)
Unknown1 (1.8%)
Required4 (7.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None54 (98.2%)
Unknown1 (1.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Autotrace Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Autotrace Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Autotrace Project's Products

View all 2 CNAs →

Top CWEs