Netpbm Project maintains a small, foundational graphics-conversion library whose narrow product scope belies broader downstream impact through embedding in numerous image-processing pipelines and tools. The recurring vulnerability patterns—out-of-bounds reads and writes, resource-exhaustion conditions, and NULL-pointer dereferences—reflect the memory-safety demands inherent to low-level image parsing and format handling in C. Defenders should inventory products that link Netpbm rather than tracking the library alone, since a single flaw can propagate across dependent codebases; current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netpbm Project over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0146HIGH Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overf | Mar 31, 2003 | 7.5 | 27 | NO | NO |
CVE-2017-2581HIGH An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution. | Jul 27, 2018 | 7.8 | 26 | NO | NO |
CVE-2009-4274HIGH Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly ex | Feb 12, 2010 | 7.5 | 25 | NO | NO |
CVE-2017-5849MEDIUM tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) | Mar 15, 2017 | 5.5 | 21 | NO | NO |
CVE-2008-0554MEDIUM Buffer overflow in the readImageData function in giftopnm.c in netpbm before 10.27 in netpbm before 10.27 allows remote user-assisted attackers to cause a denial of service (crash) | Feb 8, 2008 | 6.8 | 21 | NO | NO |
CVE-2005-2978HIGH pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics | Oct 18, 2005 | 7.5 | 21 | NO | NO |
CVE-2017-2580HIGH An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution. | Jul 27, 2018 | 7.8 | 20 | NO | NO |
CVE-2017-2579HIGH An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file co | Jul 27, 2018 | 7.8 | 20 | NO | NO |
CVE-2018-8975MEDIUM The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted ima | Mar 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2005-2471HIGH pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external u | Aug 5, 2005 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netpbm Project.
Media articles that mention a CVE ID that affects a product developed by Netpbm Project — matched by CVE ID, not by vendor name.