CVE Tools

Graphicsmagick

126 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Graphicsmagick, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Graphicsmagick CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Graphicsmagick CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-032
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-081
2026-090

Severity

How the 126 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1814%
  • High4637%
  • Medium6149%

Latest CVEs

The 15 most recently published vulnerabilities affecting Graphicsmagick.

  1. CVE-2026-77118Out-of-bounds write in GraphicsMagick PCD decoder—
  2. CVE-2025-32460GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.4.0
  3. CVE-2025-27796ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.4.5
  4. CVE-2025-27795ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.4.3
  5. CVE-2020-21679Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.5.5
  6. CVE-2022-1270In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.7.8
  7. CVE-2020-12672GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.7.5
  8. CVE-2020-10938GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.9.8
  9. CVE-2019-12921In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.6.5
  10. CVE-2019-19950In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.9.8
  11. CVE-2019-19951In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.9.8
  12. CVE-2019-19953In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.9.1
  13. CVE-2019-11506In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial...8.8
  14. CVE-2019-11505In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of ...8.8
  15. CVE-2019-11474coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CV...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store