Autotrace Project maintains a single image-tracing utility that, despite a narrow product scope, sits among the more prominent entries in the vulnerability landscape, likely reflecting its use in document processing pipelines and embedded imaging workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in memory-safety weakness classes including out-of-bounds reads and writes, integer overflows, use-after-free conditions, and improper buffer-bounds restrictions—defects characteristic of native-code image parsers handling untrusted input. The recurrence of these low-level flaw patterns reflects Autotrace's role in parsing complex image formats with minimal overhead, creating a persistent attack surface where format-parsing logic interacts directly with memory allocation. Defenders should treat Autotrace flaws as high-priority when the utility is deployed in internet-facing or batch-processing contexts, particularly in document-conversion infrastructure where malformed images can trigger memory corruption. Current exploitation activity, KEV listing status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Autotrace Project over time
Signals from CVEs in this vendor scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9194CRITICAL libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:559:29. | May 23, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-9200CRITICAL libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:528:63. | May 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-9187CRITICAL libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:486:7. | May 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-9173CRITICAL libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:497:29. | May 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-9167CRITICAL libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:337:25. | May 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-9164CRITICAL libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:16:11. | May 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-9161CRITICAL libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in autotrace.c:188:23. | May 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-9151CRITICAL libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the pnm_load_ascii function in input-pnm.c:303:12. | May 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-9191CRITICAL libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the rle_fread function in input-tga.c:252:15. | May 23, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-9185CRITICAL libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:319:7. | May 23, 2017 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (55 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Autotrace Project.
Media articles that mention a CVE ID that affects a product developed by Autotrace Project — matched by CVE ID, not by vendor name.