CVE-2019-12921

6.5
MEDIUMCVSS v3.1 Base Score
8.00%
LOW RiskEPSS (95th percentile)

In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.

Published: 3/18/2020
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVSS v2 Score

4.3

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Score (Exploitation Probability)

8.00%LOW Exploitation Risk
95th percentile

This vulnerability has a 8.00% probability of being exploited in the next 30 days, ranking higher than 95% of all scored CVEs.

CWE Classification

Advertisement