netpbm 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
公開された問題は バッファオーバーフロー、vendor risk memory corruption、vendor risk denial of service, and vendor risk integer handling に関連することが多く、vendor surface production workloads and vendor surface software deployment の文脈で アプリケーションクラッシュ and vendor impact memory corruption などの暴露リスクを伴う場合があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2009-4274 | Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value. | [email protected] | 7.5 | 2.54% | 2010-02-12 | 2026-04-29 |
| CVE-2008-4799 | pamperspective in Netpbm before 10.35.48 does not properly calculate a window height, which allows context-dependent attackers to cause a denial of service (crash) via a crafted image file that triggers an out-of-bounds read. | [email protected] | 4.3 | 0.54% | 2008-10-31 | 2026-04-23 |
| CVE-2008-0554 | Buffer overflow in the readImageData function in giftopnm.c in netpbm before 10.27 in netpbm before 10.27 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484. | [email protected] | 6.8 | 2.21% | 2008-02-08 | 2026-04-23 |
| CVE-2006-3145 | Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code when assembling the header, possibly related to an off-by-one error. | [email protected] | 5.0 | 3.75% | 2006-06-22 | 2026-04-16 |
| CVE-2005-3632 | Multiple buffer overflows in pnmtopng in netpbm 10.0 and earlier allow attackers to execute arbitrary code via a crafted PNM file. | [email protected] | 4.6 | 0.24% | 2005-11-21 | 2026-04-16 |
| CVE-2005-2978 | pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack. | [email protected] | 7.5 | 4.58% | 2005-10-18 | 2026-04-16 |
| CVE-2005-2471 | pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands. | [email protected] | 7.5 | 2.05% | 2005-08-05 | 2026-04-16 |
| CVE-2003-0924 | netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files. | [email protected] | 3.7 | 0.06% | 2004-02-17 | 2026-04-16 |
| CVE-2003-0146 | Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows. | [email protected] | 7.5 | 3.88% | 2003-03-31 | 2026-04-16 |