rpm package
opensuse/ImageMagick&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
Vulnerabilities (225)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-61861 | Low | 3.7 | < 7.1.2.27-2.1 | 7.1.2.27-2.1 | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or co | |
| CVE-2026-61858 | Low | 3.3 | < 7.1.2.27-2.1 | 7.1.2.27-2.1 | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process. | |
| CVE-2026-61857 | Low | 3.7 | < 7.1.2.27-2.1 | 7.1.2.27-2.1 | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes. | |
| CVE-2026-61465 | Low | 3.3 | < 7.1.2.27-2.1 | 7.1.2.27-2.1 | Jul 11, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulti | |
| CVE-2026-56372 | Low | 3.3 | < 7.1.2.27-2.1 | 7.1.2.27-2.1 | Jul 11, 2026 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial | |
| CVE-2026-56373 | Low | 3.7 | < 7.1.2.27-2.1 | 7.1.2.27-2.1 | Jul 10, 2026 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory. | |
| CVE-2026-56366 | Low | 3.3 | < 7.1.2.27-2.1 | 7.1.2.27-2.1 | Jul 10, 2026 | ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion. | |
| CVE-2026-56374 | Low | 3.3 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 8, 2026 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or informati | |
| CVE-2026-56362 | Low | 3.3 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 8, 2026 | ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow | |
| CVE-2026-55628 | Med | 5.5 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. Thi | |
| CVE-2026-55597 | Med | 5.5 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26. | |
| CVE-2026-55595 | Med | 4.7 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-5 | |
| CVE-2026-55594 | Med | 5.3 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in version | |
| CVE-2026-55577 | Med | 5.9 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has be | |
| CVE-2026-55510 | Med | 5.5 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur. This issue has been fixed in v | |
| CVE-2026-53467 | Med | 5.3 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has bee | |
| CVE-2026-53466 | Med | 6.5 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This | |
| CVE-2026-56377 | Low | 3.3 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jun 30, 2026 | ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended bounda | |
| CVE-2026-56365 | Low | 3.7 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jun 30, 2026 | ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service. | |
| CVE-2026-56364 | Low | 1.9 | < 7.1.2.27-1.1 | 7.1.2.27-1.1 | Jun 30, 2026 | ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files t |
- affected < 7.1.2.27-2.1fixed 7.1.2.27-2.1
ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or co
- affected < 7.1.2.27-2.1fixed 7.1.2.27-2.1
ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.
- affected < 7.1.2.27-2.1fixed 7.1.2.27-2.1
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.
- affected < 7.1.2.27-2.1fixed 7.1.2.27-2.1
ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulti
- affected < 7.1.2.27-2.1fixed 7.1.2.27-2.1
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial
- affected < 7.1.2.27-2.1fixed 7.1.2.27-2.1
ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.
- affected < 7.1.2.27-2.1fixed 7.1.2.27-2.1
ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or informati
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. Thi
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26.
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-5
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in version
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has be
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur. This issue has been fixed in v
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has bee
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended bounda
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.
- affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files t
Page 2 of 12