VYPR

rpm package

opensuse/ImageMagick&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed

Vulnerabilities (225)

  • CVE-2019-11506HigApr 24, 2019
    affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1

    In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. Thi

  • CVE-2019-11007HigApr 8, 2019
    affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1

    In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.

  • CVE-2019-7398HigFeb 5, 2019
    affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1

    In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.

  • CVE-2018-17966MedOct 3, 2018
    affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1

    ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c.

  • CVE-2018-16641MedSep 6, 2018
    affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1

    ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.

  • CVE-2018-16328CriSep 1, 2018
    affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1

    In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.

  • CVE-2018-14434MedJul 20, 2018
    affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1

    ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.

  • CVE-2018-10805MedMay 8, 2018
    affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1

    ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.

  • CVE-2018-9135HigMar 30, 2018
    affected < 7.1.0.8-1.2fixed 7.1.0.8-1.2

    In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c.

  • CVE-2016-5118CriJun 10, 2016
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

  • CVE-2016-3718MedKEVMay 5, 2016
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

  • CVE-2016-3717MedMay 5, 2016
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

  • CVE-2016-3716LowMay 5, 2016
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.

  • CVE-2016-3715MedKEVMay 5, 2016
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

  • CVE-2016-3714HigKEVMay 5, 2016
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

  • CVE-2012-1186MedJun 5, 2012
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fi

  • CVE-2012-1185HigJun 5, 2012
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF

  • CVE-2012-0248MedJun 5, 2012
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.

  • CVE-2012-0247HigJun 5, 2012
    affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1

    ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.

  • CVE-2007-4987Sep 24, 2007
    affected < 7.1.0.8-1.2fixed 7.1.0.8-1.2

    Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.

Page 11 of 12