CVE-2009-1364: Fixed realloc return value usage (bsc#495842, bnc#831299)
CVE-2015-0848: Heap overflow on libwmf0.2-7 (bsc#933109)
CVE-2015-4588: DecodeImage() did not check that the run-length 'count' fits into the total size of the image, which could lead to a heap-based buffer overflow (bsc#933109)
CVE-2015-4695: meta_pen_create heap buffer over read (bsc#936058)