Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Graphicsmagick

First CVE: Apr 25, 2005Active for: 21 yearsTotal CVEs: 121
43.4
VTI Score
High

GraphicsMagick is an image-processing library embedded across a broad range of web applications, content-management systems, and server-side image-handling pipelines, despite its single-product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity that reflects the memory-safety demands of parsing and manipulating diverse image formats in untrusted data contexts. The recurring exposure pattern centers on out-of-bounds memory access, buffer-boundary violations, NULL-pointer dereferences, and input-validation gaps—weaknesses characteristic of a C-based library operating on complex binary structures with minimal trust boundaries. Defenders should treat image-processing endpoints as attack-surface priorities and maintain close tracking of upstream patch availability, since this library's embedded role means remediation depends on downstream vendors and application operators rebuilding their dependencies. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
121
Total CVEs
More Total CVEs than 99% of tracked vendors
8.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Graphicsmagick over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2005
21 years ago
Most Recent CVE
Apr 9, 2025
471 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (121 CVEs).

121 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-5118CRITICAL
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filenam
Jun 10, 20169.859NONO
CVE-2017-16352HIGH
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magic
Nov 1, 20178.847NOYES
CVE-2017-14103HIGH
The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote at
Sep 1, 20178.841NONO
CVE-2017-16353MEDIUM
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buff
Nov 1, 20176.540NOYES
CVE-2017-12936HIGH
The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.
Aug 18, 20178.836NONO
CVE-2017-11403HIGH
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.
Jul 18, 20178.835NONO
CVE-2019-11005CRITICAL
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial
Apr 8, 20199.832NONO
CVE-2016-7447CRITICAL
Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.
Feb 6, 20179.832NONO
CVE-2017-15277MEDIUM
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palett
Oct 12, 20176.531NONO
CVE-2019-19951CRITICAL
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
Dec 24, 20199.830NONO
View all 121 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products121 CVEs
45%
41%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local16 (13.2%)
Network93 (76.9%)
Unknown12 (9.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low107 (88.4%)
High2 (1.7%)
Unknown12 (9.9%)
User Interaction
None27 (22.3%)
Unknown12 (9.9%)
Required82 (67.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None109 (90.1%)
Unknown12 (9.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (121 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
2.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Graphicsmagick.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Graphicsmagick — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Graphicsmagick's Products

View all 2 CNAs →

Top CWEs