Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Potrace Project

First CVE: Jan 31, 2017Active for: 9 yearsTotal CVEs: 14
44.1
VTI Score
High

Potrace is a widely used raster-to-vector conversion utility that occupies a notable position in the graphics and document-processing toolchain, embedded across scanning software, image converters, and design applications. Its vulnerability profile centers on the parsing of bitmap image data and recurs through memory-safety weakness classes including buffer-boundary violations, NULL-pointer dereferences, out-of-bounds reads, and divide-by-zero conditions, reflecting the low-level pixel manipulation and mathematical operations inherent to vectorization. Defenders should ensure timely updates for products that bundle this utility, as untrusted or malformed image inputs can trigger these flaws; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
14.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Potrace Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2017
9 years ago
Most Recent CVE
Aug 1, 2017
3,279 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-8701HIGH
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe
Jan 31, 20177.824NONO
CVE-2016-8700HIGH
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe
Jan 31, 20177.823NONO
CVE-2016-8699HIGH
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe
Jan 31, 20177.823NONO
CVE-2017-7263HIGH
The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly hav
Mar 26, 20177.820NONO
CVE-2016-8703HIGH
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe
Jan 31, 20177.820NONO
CVE-2016-8702HIGH
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe
Jan 31, 20177.820NONO
CVE-2016-8698HIGH
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe
Jan 31, 20177.820NONO
CVE-2016-8694MEDIUM
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image
Jan 31, 20175.520NONO
CVE-2016-8686HIGH
The bm_new function in bitmap.h in potrace 1.13 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure.
Jan 31, 20177.820NONO
CVE-2017-12067HIGH
Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
Aug 1, 20177.519NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
36%
64%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local13 (92.9%)
Network1 (7.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (7.1%)
Unknown0 (0.0%)
Required13 (92.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Potrace Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Potrace Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Potrace Project's Products

View all 1 CNAs →

Top CWEs