VYPR

apk package

chainguard/imagemagick-6

pkg:apk/chainguard/imagemagick-6

Vulnerabilities (66)

  • CVE-2022-0284HigAug 29, 2022
    affected < 0fixed 0

    A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can p

  • CVE-2022-2719MedAug 10, 2022
    affected < 0fixed 0

    In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.

  • CVE-2021-3596MedFeb 24, 2022
    affected < 0fixed 0

    A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentat

  • CVE-2020-27769LowMay 14, 2021
    affected < 0fixed 0

    In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.

  • CVE-2021-20313HigMay 11, 2021
    affected < 0fixed 0

    A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.

  • CVE-2021-20312HigMay 11, 2021
    affected < 0fixed 0

    A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threa

  • CVE-2021-20311HigMay 11, 2021
    affected < 0fixed 0

    A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero in sRGBTransformImage() in the MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker processed by an application using ImageMagick. The h

  • CVE-2021-20310HigMay 11, 2021
    affected < 0fixed 0

    A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero ConvertXYZToJzazbz() of MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The high

  • CVE-2020-27829MedMar 26, 2021
    affected < 0fixed 0

    A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.

  • CVE-2021-20244MedMar 9, 2021
    affected < 0fixed 0

    A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20243MedMar 9, 2021
    affected < 0fixed 0

    A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

  • CVE-2020-27768LowFeb 23, 2021
    affected < 0fixed 0

    In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h. This flaw affects ImageMagick versions prior to 7.0.9-0.

  • CVE-2020-25663MedDec 8, 2020
    affected < 0fixed 0

    A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or heap-buffer-overflow READ when GetPixelRed() or GetPixelBlue() was called. This could occur if an attacker is able to submit a malicious image fi

  • CVE-2019-17547HigOct 14, 2019
    affected < 0fixed 0

    In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/draw.c has a use-after-free.

  • CVE-2019-13136HigJul 1, 2019
    affected < 0fixed 0

    ImageMagick before 7.0.8-50 has an integer overflow vulnerability in the function TIFFSeekCustomStream in coders/tiff.c.

  • CVE-2018-16329CriSep 1, 2018
    affected < 0fixed 0

    In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the GetMagickProperty function in MagickCore/property.c.

  • CVE-2018-16328CriSep 1, 2018
    affected < 0fixed 0

    In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.

  • CVE-2017-11447MedJul 19, 2017
    affected < 0fixed 0

    The ReadSCREENSHOTImage function in coders/screenshot.c in ImageMagick before 7.0.6-1 has memory leaks, causing denial of service.

  • CVE-2016-7538MedApr 20, 2017
    affected < 0fixed 0

    coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.

  • CVE-2016-7514MedApr 20, 2017
    affected < 0fixed 0

    The ReadPSDChannelPixels function in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.