GraphicsMagick is an image-processing library embedded across a broad range of web applications, content-management systems, and server-side image-handling pipelines, despite its single-product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity that reflects the memory-safety demands of parsing and manipulating diverse image formats in untrusted data contexts. The recurring exposure pattern centers on out-of-bounds memory access, buffer-boundary violations, NULL-pointer dereferences, and input-validation gaps—weaknesses characteristic of a C-based library operating on complex binary structures with minimal trust boundaries. Defenders should treat image-processing endpoints as attack-surface priorities and maintain close tracking of upstream patch availability, since this library's embedded role means remediation depends on downstream vendors and application operators rebuilding their dependencies. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graphicsmagick over time
Signals from CVEs in this vendor scope (121 CVEs).
121 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5118CRITICAL The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filenam | Jun 10, 2016 | 9.8 | 59 | NO | NO |
CVE-2017-16352HIGH GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magic | Nov 1, 2017 | 8.8 | 47 | NO | YES |
CVE-2017-14103HIGH The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote at | Sep 1, 2017 | 8.8 | 41 | NO | NO |
CVE-2017-16353MEDIUM GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buff | Nov 1, 2017 | 6.5 | 40 | NO | YES |
CVE-2017-12936HIGH The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting. | Aug 18, 2017 | 8.8 | 36 | NO | NO |
CVE-2017-11403HIGH The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file. | Jul 18, 2017 | 8.8 | 35 | NO | NO |
CVE-2019-11005CRITICAL In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial | Apr 8, 2019 | 9.8 | 32 | NO | NO |
CVE-2016-7447CRITICAL Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors. | Feb 6, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-15277MEDIUM ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palett | Oct 12, 2017 | 6.5 | 31 | NO | NO |
CVE-2019-19951CRITICAL In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c. | Dec 24, 2019 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (121 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graphicsmagick.
Media articles that mention a CVE ID that affects a product developed by Graphicsmagick — matched by CVE ID, not by vendor name.