An error in IDE_ACDStd.apl when allocating memory based on values in the Logical Screen Descriptor structure of a GIF image and later copying data into the buffer without ensuring that it's adequately sized can be exploited to corrupt heap memory.
The vulnerabilities are confirmed in version 5.1 (Build 137). Other versions may also be affected.