CVE-2016-8702: Potrace Project Potrace

High severity, CVSS 7.8. EPSS: 2% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-2016-8701, and CVE-2016-8703.

Affected products

Published 2017-01-31. Last modified 2026-06-17.