VYPR

apk package

chainguard/imagemagick-6

pkg:apk/chainguard/imagemagick-6

Vulnerabilities (68)

  • CVE-2026-62363MedJul 30, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.

  • CVE-2026-66011LowJul 25, 2026
    affected < 0fixed 0

    ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

  • CVE-2026-61859LowJul 15, 2026
    affected < 6.9.13.51-r0fixed 6.9.13.51-r0

    ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

  • CVE-2026-56372LowJul 11, 2026
    affected < 0fixed 0

    ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial

  • CVE-2026-56374LowJul 8, 2026
    affected < 0fixed 0

    ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or informati

  • CVE-2026-55597MedJul 1, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26.

  • CVE-2026-56364LowJun 30, 2026
    affected < 0fixed 0

    ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files t

  • CVE-2026-53465MedJun 10, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.

  • CVE-2026-53464MedJun 10, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched in version 7.1.2-25.

  • CVE-2026-48724MedJun 10, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg dithering method it will cause a negative heap buffer over-write. This issue has been patched in version 7.1

  • CVE-2026-46557MedJun 10, 2026
    affected < 6.9.13.50-r0fixed 6.9.13.50-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument. This issue has been patched in version 7.1.2-23.

  • CVE-2026-46523MedJun 10, 2026
    affected < 6.9.13.48-r0fixed 6.9.13.48-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue.

  • CVE-2026-46522HigJun 10, 2026
    affected < 6.9.13.48-r0fixed 6.9.13.48-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.

  • CVE-2026-33536MedMar 26, 2026
    affected < 6.9.13.43-r0fixed 6.9.13.43-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, due to an incorrect return value on certain platforms a pointer is incremented past the end of a buffer that is on the stack and that could result in an

  • CVE-2026-33535MedMar 26, 2026
    affected < 6.9.13.43-r0fixed 6.9.13.43-r0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the

  • CVE-2026-30935MedMar 10, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, BilateralBlurImage contains a heap buffer over-read caused by an incorrect conversion. When processing a crafted image with the -bilateral-blur operation an

  • CVE-2026-30931MedMar 10, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, a heap-based buffer overflow in the UHDR encoder can happen due to truncation of a value and it would allow an out of bounds write. This vulnerability is fix

  • CVE-2026-28493MedMar 10, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image.

  • CVE-2026-25969MedFeb 24, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak exists in `coders/ashlar.c`. The `WriteASHLARImage` allocates a structure. However, when an exception is thrown, the allocated memory is not pr

  • CVE-2026-25794HigFeb 24, 2026
    affected < 0fixed 0

    ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-b

Page 1 of 4