Vulnerabilities > Libgd

DATE CVE VULNERABILITY TITLE RISK
2017-03-15 CVE-2016-10168 Integer Overflow or Wraparound vulnerability in Libgd
Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.
local
low complexity
libgd CWE-190
7.8
2017-03-15 CVE-2016-10167 Improper Input Validation vulnerability in Libgd
The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
local
low complexity
libgd CWE-20
5.5
2017-03-15 CVE-2016-10166 Integer Underflow (Wrap or Wraparound) vulnerability in Libgd
Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.
network
low complexity
libgd CWE-191
critical
9.8
2017-03-15 CVE-2016-6906 Out-of-bounds Read vulnerability in Libgd
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.
local
low complexity
libgd CWE-125
5.5
2017-01-26 CVE-2016-9317 Improper Input Validation vulnerability in Libgd
The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image.
local
low complexity
libgd CWE-20
5.5
2017-01-26 CVE-2016-6912 Double Free vulnerability in Libgd
Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
network
low complexity
libgd CWE-415
critical
9.8
2017-01-26 CVE-2016-6911 Out-of-bounds Read vulnerability in Libgd
The dynamicGetbuf function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.
local
low complexity
libgd CWE-125
5.5
2017-01-04 CVE-2016-9933 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libgd 2.2.1
Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefilltoborder call that triggers use of a negative color value.
network
low complexity
libgd CWE-119
7.5
2017-01-04 CVE-2016-8670 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libgd
Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted imagecreatefromstring call.
network
low complexity
libgd CWE-119
critical
9.8
2016-10-03 CVE-2016-6905 Out-of-bounds Read vulnerability in multiple products
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA image.
network
low complexity
libgd opensuse CWE-125
6.5