Netpbm is a niche collection of image-format conversion and manipulation tools that, despite minimal product breadth, maintains presence across Unix-like systems and embedded environments where legacy image processing remains necessary. The recurring vulnerability signals center on memory-buffer handling issues, reflecting the low-level nature of image parsing and the challenges of safely processing untrusted binary format data. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netpbm over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0146HIGH Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overf | Mar 31, 2003 | 7.5 | 27 | NO | NO |
CVE-2017-2581HIGH An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution. | Jul 27, 2018 | 7.8 | 26 | NO | NO |
CVE-2009-4274HIGH Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly ex | Feb 12, 2010 | 7.5 | 25 | NO | NO |
CVE-2017-5849MEDIUM tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) | Mar 15, 2017 | 5.5 | 21 | NO | NO |
CVE-2008-0554MEDIUM Buffer overflow in the readImageData function in giftopnm.c in netpbm before 10.27 in netpbm before 10.27 allows remote user-assisted attackers to cause a denial of service (crash) | Feb 8, 2008 | 6.8 | 21 | NO | NO |
CVE-2005-2978HIGH pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics | Oct 18, 2005 | 7.5 | 21 | NO | NO |
CVE-2017-2580HIGH An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution. | Jul 27, 2018 | 7.8 | 20 | NO | NO |
CVE-2017-2579HIGH An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file co | Jul 27, 2018 | 7.8 | 20 | NO | NO |
CVE-2018-8975MEDIUM The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted ima | Mar 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2005-2471HIGH pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external u | Aug 5, 2005 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netpbm.
Media articles that mention a CVE ID that affects a product developed by Netpbm — matched by CVE ID, not by vendor name.