Medium
CVSS: 4.0
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.
Medium
CVSS: 4.5
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
Medium
CVSS: 4.3
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.