Potrace is a widely used raster-to-vector conversion utility that occupies a notable position in the graphics and document-processing toolchain, embedded across scanning software, image converters, and design applications. Its vulnerability profile centers on the parsing of bitmap image data and recurs through memory-safety weakness classes including buffer-boundary violations, NULL-pointer dereferences, out-of-bounds reads, and divide-by-zero conditions, reflecting the low-level pixel manipulation and mathematical operations inherent to vectorization. Defenders should ensure timely updates for products that bundle this utility, as untrusted or malformed image inputs can trigger these flaws; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Potrace Project over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-8701HIGH Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe | Jan 31, 2017 | 7.8 | 24 | NO | NO |
CVE-2016-8700HIGH Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe | Jan 31, 2017 | 7.8 | 23 | NO | NO |
CVE-2016-8699HIGH Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe | Jan 31, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-7263HIGH The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly hav | Mar 26, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-8703HIGH Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe | Jan 31, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-8702HIGH Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe | Jan 31, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-8698HIGH Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a diffe | Jan 31, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-8694MEDIUM The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image | Jan 31, 2017 | 5.5 | 20 | NO | NO |
CVE-2016-8686HIGH The bm_new function in bitmap.h in potrace 1.13 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. | Jan 31, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-12067HIGH Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c. | Aug 1, 2017 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Potrace Project.
Media articles that mention a CVE ID that affects a product developed by Potrace Project — matched by CVE ID, not by vendor name.