VYPR

apk package

chainguard/imagemagick-6

pkg:apk/chainguard/imagemagick-6

Vulnerabilities (66)

  • CVE-2026-61859Jul 16, 2026
    affected < 6.9.13.51-r0fixed 6.9.13.51-r0

    ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

  • CVE-2026-56372modJul 11, 2026
    affected < 0fixed 0

    ImageMagick: ImageMagick: Information Disclosure and Denial of Service

  • CVE-2026-56374Jul 9, 2026
    affected < 0fixed 0

    ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or informati

  • CVE-2026-55597Jul 2, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26.

  • CVE-2026-56364Jul 1, 2026
    affected < 0fixed 0

    ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files t

  • CVE-2026-53465MedJun 10, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.

  • CVE-2026-53464MedJun 10, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched in version 7.1.2-25.

  • CVE-2026-48724MedJun 10, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg dithering method it will cause a negative heap buffer over-write. This issue has been patched in version 7.1

  • CVE-2026-46557MedJun 10, 2026
    affected < 6.9.13.50-r0fixed 6.9.13.50-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument. This issue has been patched in version 7.1.2-23.

  • CVE-2026-46523MedJun 10, 2026
    affected < 6.9.13.48-r0fixed 6.9.13.48-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue.

  • CVE-2026-46522HigJun 10, 2026
    affected < 6.9.13.48-r0fixed 6.9.13.48-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.

  • CVE-2026-33536MedMar 26, 2026
    affected < 6.9.13.43-r0fixed 6.9.13.43-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, due to an incorrect return value on certain platforms a pointer is incremented past the end of a buffer that is on the stack and that could result in an

  • CVE-2026-33535MedMar 26, 2026
    affected < 6.9.13.43-r0fixed 6.9.13.43-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the

  • CVE-2026-30935Mar 9, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, BilateralBlurImage contains a heap buffer over-read caused by an incorrect conversion. When processing a crafted image with the -bilateral-blur operation an

  • CVE-2026-30931Mar 9, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, a heap-based buffer overflow in the UHDR encoder can happen due to truncation of a value and it would allow an out of bounds write. This vulnerability is fix

  • CVE-2026-28493Mar 9, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image.

  • CVE-2026-25969Feb 24, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak exists in `coders/ashlar.c`. The `WriteASHLARImage` allocates a structure. However, when an exception is thrown, the allocated memory is not pr

  • CVE-2026-25794Feb 24, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-b

  • CVE-2026-25637Feb 24, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image that results in small objects that are allo

  • CVE-2026-23952MedJan 22, 2026
    affected < 6.9.13.38-r0fixed 6.9.13.38-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can

Page 1 of 4