VYPR

imagemagick

by Debian

Source repositories

CVEs (11)

  • CVE-2026-61871LowJul 15, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

  • CVE-2026-61868LowJul 15, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).

  • CVE-2026-61860LowJul 15, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial…

  • CVE-2026-61869LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.

  • CVE-2026-61867LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.

  • CVE-2026-61866LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

  • CVE-2026-61865LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.

  • CVE-2026-61864LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released.

  • CVE-2026-61862LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This…

  • CVE-2026-61872LowJul 15, 2026
    risk 0.09cvss 2.5epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes allocated memory not to be released, which can lead to increased memory consumption.

  • CVE-2026-61464LowJul 15, 2026
    risk 0.05cvss 1.8epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.