VYPR

rpm package

opensuse/ImageMagick&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed

Vulnerabilities (225)

  • CVE-2026-56363LowJun 30, 2026
    affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1

    ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application crash

  • CVE-2026-56361LowJun 30, 2026
    affected < 7.1.2.27-1.1fixed 7.1.2.27-1.1

    ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.

  • CVE-2026-56370LowJun 24, 2026
    affected < 7.1.2.25-3.1fixed 7.1.2.25-3.1

    ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI,

  • CVE-2026-56368LowJun 24, 2026
    affected < 7.1.2.25-3.1fixed 7.1.2.25-3.1

    ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.

  • CVE-2026-56379HigJun 23, 2026
    affected < 7.1.2.25-3.1fixed 7.1.2.25-3.1

    ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during render

  • CVE-2026-56376LowJun 23, 2026
    affected < 7.1.2.25-3.1fixed 7.1.2.25-3.1

    ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

  • CVE-2026-56371MedJun 23, 2026
    affected < 7.1.2.25-3.1fixed 7.1.2.25-3.1

    ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture att

  • CVE-2026-56367LowJun 21, 2026
    affected < 7.1.2.25-3.1fixed 7.1.2.25-3.1

    ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. Processing a crafted PSB file can lead to information disclosure o

  • CVE-2026-53465MedJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.

  • CVE-2026-53463MedJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when passing incorrect arguments in the distort operation a null pointer deference will occur. This issue has been patched in versions 6.9.13-5

  • CVE-2026-53462MedJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when an allocation fails in CheckPrimitiveExtent this can result in a heap-use-after-free and result in a crash. This issue has been patched in

  • CVE-2026-53461HigJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6

  • CVE-2026-53460HigJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in ver

  • CVE-2026-49219MedJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue h

  • CVE-2026-49218HigJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue

  • CVE-2026-48994MedJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in v

  • CVE-2026-48734MedJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13

  • CVE-2026-48724MedJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg dithering method it will cause a negative heap buffer over-write. This issue has been patched in version 7.1

  • CVE-2026-47166MedJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This issue has been

  • CVE-2026-47165MedJun 10, 2026
    affected < 7.1.2.25-2.1fixed 7.1.2.25-2.1

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, the distributed pixel cache was originally designed to operate without a challenge–response authentication model. This has been changed in vers

Page 3 of 12