rpm package
opensuse/ImageMagick&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
Vulnerabilities (225)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-64685 | Med | 5.3 | < 7.1.2.28-2.1 | 7.1.2.28-2.1 | Jul 30, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed | |
| CVE-2026-62946 | Med | 5.1 | < 7.1.2.28-1.1 | 7.1.2.28-1.1 | Jul 30, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This iss | |
| CVE-2026-62363 | Med | 5.0 | < 7.1.2.28-1.1 | 7.1.2.28-1.1 | Jul 30, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27. | |
| CVE-2026-62343 | Med | 4.7 | < 7.1.2.28-1.1 | 7.1.2.28-1.1 | Jul 30, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied | |
| CVE-2026-66011 | Low | 3.3 | < 7.1.2.28-1.1 | 7.1.2.28-1.1 | Jul 25, 2026 | ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources. | |
| CVE-2026-61872 | Low | 2.5 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes allocated memory not to be released, which can lead to increased memory consumption. | |
| CVE-2026-61871 | Low | 3.7 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service. | |
| CVE-2026-61869 | Low | 2.9 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service. | |
| CVE-2026-61868 | Low | 3.7 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service). | |
| CVE-2026-61867 | Low | 2.9 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service. | |
| CVE-2026-61866 | Low | 2.9 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion. | |
| CVE-2026-61865 | Low | 2.9 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs. | |
| CVE-2026-61864 | Low | 2.9 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released. | |
| CVE-2026-61863 | Low | 2.9 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak. | |
| CVE-2026-61862 | Low | 2.9 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This | |
| CVE-2026-61860 | Low | 3.7 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of | |
| CVE-2026-61859 | Low | 3.3 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy. | |
| CVE-2026-61464 | Low | 1.8 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service. | |
| CVE-2026-56375 | Low | 3.3 | < 7.1.2.27-3.1 | 7.1.2.27-3.1 | Jul 15, 2026 | ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service. | |
| CVE-2026-61870 | Low | 2.9 | < 7.1.2.27-2.1 | 7.1.2.27-2.1 | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service. |
- affected < 7.1.2.28-2.1fixed 7.1.2.28-2.1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed
- affected < 7.1.2.28-1.1fixed 7.1.2.28-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This iss
- affected < 7.1.2.28-1.1fixed 7.1.2.28-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.
- affected < 7.1.2.28-1.1fixed 7.1.2.28-1.1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied
- affected < 7.1.2.28-1.1fixed 7.1.2.28-1.1
ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes allocated memory not to be released, which can lead to increased memory consumption.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.
- affected < 7.1.2.27-3.1fixed 7.1.2.27-3.1
ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service.
- affected < 7.1.2.27-2.1fixed 7.1.2.27-2.1
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.
Page 1 of 12