libgd records
39 published records for vendor libgd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 97.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read10
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-415 Double Free5
- CWE-190 Integer Overflow or Wraparound4
- CWE-20 Improper Input Validation3
- CWE-399 Resource Management Errors2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
39 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
56Plan | CVE-2019-6977Proof of concept | gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.libgd · libgd · CWE-787 | High8.8 | — | 71.5% | Jan 26, 2019 |
50Plan | CVE-2016-3074Proof of concept | Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or libgd · libgd · CWE-681 | Critical9.8 | — | 37.2% | Apr 26, 2016 |
42Plan | CVE-2016-10166No exploit | Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remlibgd · libgd · CWE-191 | Critical9.8 | — | 10.7% | Mar 15, 2017 |
41Plan | CVE-2016-7568No exploit | Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.libgd · libgd · CWE-190 | Critical9.8 | — | 5.1% | Sep 28, 2016 |
40Plan | CVE-2009-3546No exploit | The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certaphp · php · CWE-119 | Critical9.3 | — | 10.3% | Oct 19, 2009 |
40Plan | CVE-2016-8670No exploit | Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP belibgd · libgd · CWE-119 | Critical9.8 | — | 4.8% | Jan 4, 2017 |
40Plan | CVE-2016-6912No exploit | Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have libgd · libgd · CWE-415 | Critical9.8 | — | 4.5% | Jan 26, 2017 |
40Plan | CVE-2019-6978No exploit | The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c.libgd · libgd · CWE-415 | Critical9.8 | — | 4.5% | Jan 28, 2019 |
37Monitor | CVE-2016-5766No exploit | Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37libgd · libgd · CWE-190 | High8.8 | — | 7.5% | Aug 7, 2016 |
37Monitor | CVE-2016-5767No exploit | Integer overflow in the gdImageCreate function in gd.c in the GD Graphics Library (aka libgd) before 2.0.34RC1, as used in PHP before 5.5.37libgd · libgd · CWE-190 | High8.8 | — | 6.7% | Aug 7, 2016 |
37Monitor | CVE-2016-5116No exploit | gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent alibgd · libgd · CWE-119 | Critical9.1 | — | 3.8% | Aug 7, 2016 |
36Monitor | CVE-2018-1000222No exploit | Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution .libgd · libgd · CWE-415 | High8.8 | — | 4.2% | Aug 20, 2018 |
32Monitor | CVE-2016-9933No exploit | Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in libgd · libgd · CWE-119 | High7.5 | — | 6.9% | Jan 4, 2017 |
32Monitor | CVE-2016-6128No exploit | The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remolibgd · libgd · CWE-20 | High7.5 | — | 6.8% | Aug 7, 2016 |
32Monitor | CVE-2017-6362No exploit | Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectlibgd · libgd · CWE-415 | High7.5 | — | 5.1% | Sep 7, 2017 |
32Monitor | CVE-2016-10168No exploit | Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectolibgd · libgd · CWE-190 | High7.8 | — | 3.7% | Mar 15, 2017 |
32Monitor | CVE-2017-6363No exploit | In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c.libgd · libgd · CWE-125 | High8.1 | — | 1.4% | Feb 27, 2020 |
31Monitor | CVE-2013-7456No exploit | gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.libgd · libgd · CWE-125 | High7.6 | — | 3.8% | Aug 7, 2016 |
31Monitor | CVE-2015-8877No exploit | The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uslibgd · libgd · CWE-399 | High7.5 | — | 3.6% | May 21, 2016 |
31Monitor | CVE-2018-14553No exploit | gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a speciflibgd · libgd · CWE-476 | High7.5 | — | 3.4% | Feb 11, 2020 |
31Monitor | CVE-2021-40145No exploit | gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free.libgd · libgd · CWE-415 | High7.5 | — | 2.1% | Aug 25, 2021 |
28Monitor | CVE-2016-6207No exploit | Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote alibgd · libgd · CWE-119 | Medium6.5 | — | 6.3% | Aug 12, 2016 |
27Monitor | CVE-2016-6132No exploit | The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of serviclibgd · libgd · CWE-125 | Medium6.5 | — | 3.3% | Aug 12, 2016 |
27Monitor | CVE-2016-6214No exploit | gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via alibgd · libgd · CWE-125 | Medium6.5 | — | 3.2% | Aug 12, 2016 |
27Monitor | CVE-2016-6161No exploit | The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounlibgd · libgd · CWE-125 | Medium6.5 | — | 2.8% | Aug 12, 2016 |
- CVE-2019-697756Plan
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.
HighCVSS 8.8Proof of conceptEPSS 71%libgd · libgdJan 26, 2019
- CVE-2016-307450Plan
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or
CriticalCVSS 9.8Proof of conceptEPSS 37%libgd · libgdApr 26, 2016
- CVE-2016-1016642Plan
Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows rem
CriticalCVSS 9.8No exploitEPSS 11%libgd · libgdMar 15, 2017
- CVE-2016-756841Plan
Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.
CriticalCVSS 9.8No exploitEPSS 5%libgd · libgdSep 28, 2016
- CVE-2009-354640Plan
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certa
CriticalCVSS 9.3No exploitEPSS 10%php · phpOct 19, 2009
- CVE-2016-867040Plan
Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP be
CriticalCVSS 9.8No exploitEPSS 5%libgd · libgdJan 4, 2017
- CVE-2016-691240Plan
Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have
CriticalCVSS 9.8No exploitEPSS 4%libgd · libgdJan 26, 2017
- CVE-2019-697840Plan
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c.
CriticalCVSS 9.8No exploitEPSS 4%libgd · libgdJan 28, 2019
- CVE-2016-576637Monitor
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37
HighCVSS 8.8No exploitEPSS 7%libgd · libgdAug 7, 2016
- CVE-2016-576737Monitor
Integer overflow in the gdImageCreate function in gd.c in the GD Graphics Library (aka libgd) before 2.0.34RC1, as used in PHP before 5.5.37
HighCVSS 8.8No exploitEPSS 7%libgd · libgdAug 7, 2016
- CVE-2016-511637Monitor
gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent a
CriticalCVSS 9.1No exploitEPSS 4%libgd · libgdAug 7, 2016
- CVE-2018-100022236Monitor
Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution .
HighCVSS 8.8No exploitEPSS 4%libgd · libgdAug 20, 2018
- CVE-2016-993332Monitor
Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in
HighCVSS 7.5No exploitEPSS 7%libgd · libgdJan 4, 2017
- CVE-2016-612832Monitor
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remo
HighCVSS 7.5No exploitEPSS 7%libgd · libgdAug 7, 2016
- CVE-2017-636232Monitor
Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vect
HighCVSS 7.5No exploitEPSS 5%libgd · libgdSep 7, 2017
- CVE-2016-1016832Monitor
Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vecto
HighCVSS 7.8No exploitEPSS 4%libgd · libgdMar 15, 2017
- CVE-2017-636332Monitor
In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c.
HighCVSS 8.1No exploitEPSS 1%libgd · libgdFeb 27, 2020
- CVE-2013-745631Monitor
gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.
HighCVSS 7.6No exploitEPSS 4%libgd · libgdAug 7, 2016
- CVE-2015-887731Monitor
The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, us
HighCVSS 7.5No exploitEPSS 4%libgd · libgdMay 21, 2016
- CVE-2018-1455331Monitor
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specif
HighCVSS 7.5No exploitEPSS 3%libgd · libgdFeb 11, 2020
- CVE-2021-4014531Monitor
gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free.
HighCVSS 7.5No exploitEPSS 2%libgd · libgdAug 25, 2021
- CVE-2016-620728Monitor
Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote a
MediumCVSS 6.5No exploitEPSS 6%libgd · libgdAug 12, 2016
- CVE-2016-613227Monitor
The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of servic
MediumCVSS 6.5No exploitEPSS 3%libgd · libgdAug 12, 2016
- CVE-2016-621427Monitor
gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a
MediumCVSS 6.5No exploitEPSS 3%libgd · libgdAug 12, 2016
- CVE-2016-616127Monitor
The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-boun
MediumCVSS 6.5No exploitEPSS 3%libgd · libgdAug 12, 2016