Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netpbm

First CVE: Mar 31, 2003Active for: 23 yearsTotal CVEs: 16

Netpbm is a niche collection of image-format conversion and manipulation tools that, despite minimal product breadth, maintains presence across Unix-like systems and embedded environments where legacy image processing remains necessary. The recurring vulnerability signals center on memory-buffer handling issues, reflecting the low-level nature of image parsing and the challenges of safely processing untrusted binary format data. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 91% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Netpbm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2003
23 years ago
Most Recent CVE
Jul 27, 2018
2,919 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2003-0146HIGH
Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overf
Mar 31, 20037.527NONO
CVE-2017-2581HIGH
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.
Jul 27, 20187.826NONO
CVE-2009-4274HIGH
Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly ex
Feb 12, 20107.525NONO
CVE-2017-5849MEDIUM
tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write)
Mar 15, 20175.521NONO
CVE-2008-0554MEDIUM
Buffer overflow in the readImageData function in giftopnm.c in netpbm before 10.27 in netpbm before 10.27 allows remote user-assisted attackers to cause a denial of service (crash)
Feb 8, 20086.821NONO
CVE-2005-2978HIGH
pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics
Oct 18, 20057.521NONO
CVE-2017-2580HIGH
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.
Jul 27, 20187.820NONO
CVE-2017-2579HIGH
An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file co
Jul 27, 20187.820NONO
CVE-2018-8975MEDIUM
The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted ima
Mar 25, 20185.520NONO
CVE-2005-2471HIGH
pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external u
Aug 5, 20057.520NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
50%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local7 (43.8%)
Network0 (0.0%)
Unknown9 (56.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (43.8%)
High0 (0.0%)
Unknown9 (56.3%)
User Interaction
None0 (0.0%)
Unknown9 (56.3%)
Required7 (43.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (43.8%)
Unknown9 (56.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netpbm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netpbm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netpbm's Products

View all 2 CNAs →

Top CWEs