VYPR

Netpbm

by Netpbm

CVEs (16)

  • CVE-2018-8975MedMar 25, 2018
    risk 0.36cvss 5.5epss 0.02

    The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.

  • CVE-2017-5849MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.02

    tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related to transposing width and height values.

  • CVE-2017-2581MedJul 27, 2018
    risk 0.29cvss 4.5epss 0.01

    An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.

  • CVE-2017-2580MedJul 27, 2018
    risk 0.29cvss 4.5epss 0.01

    An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.

  • CVE-2017-2587LowJul 27, 2018
    risk 0.22cvss 3.3epss 0.01

    A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.

  • CVE-2017-2586LowJul 27, 2018
    risk 0.22cvss 3.3epss 0.01

    A null pointer dereference vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.

  • CVE-2017-2579LowJul 27, 2018
    risk 0.22cvss 3.3epss 0.02

    An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file could cause the application to crash or possibly allows code execution.

  • CVE-2003-0146Mar 31, 2003
    risk 0.01cvss epss 0.07

    Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer…

  • CVE-2009-4274Feb 12, 2010
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a…

  • CVE-2008-4799Oct 31, 2008
    risk 0.00cvss epss 0.02

    pamperspective in Netpbm before 10.35.48 does not properly calculate a window height, which allows context-dependent attackers to cause a denial of service (crash) via a crafted image file that triggers an out-of-bounds read.

  • CVE-2008-0554Feb 8, 2008
    risk 0.00cvss epss 0.04

    Buffer overflow in the readImageData function in giftopnm.c in netpbm before 10.27 in netpbm before 10.27 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.

  • CVE-2006-3145Jun 22, 2006
    risk 0.00cvss epss 0.05

    Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code when assembling the header, possibly related to an off-by-one error.

  • CVE-2005-3632Nov 21, 2005
    risk 0.00cvss epss 0.01

    Multiple buffer overflows in pnmtopng in netpbm 10.0 and earlier allow attackers to execute arbitrary code via a crafted PNM file.

  • CVE-2005-2978Oct 18, 2005
    risk 0.00cvss epss 0.05

    pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack.

  • CVE-2005-2471Aug 5, 2005
    risk 0.00cvss epss 0.04

    pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.

  • CVE-2003-0924Feb 17, 2004
    risk 0.00cvss epss 0.00

    netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.