VYPR

Imagemagick

by ImageMagick

Source repositories

CVEs (830)

  • CVE-2016-9556MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.05

    The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.

  • CVE-2014-9915MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.01

    Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.

  • CVE-2014-9840MedMar 22, 2017
    risk 0.36cvss 5.5epss 0.02

    ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted palm file.

  • CVE-2014-9838MedMar 22, 2017
    risk 0.36cvss 5.5epss 0.02

    magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (crash).

  • CVE-2014-9836MedMar 22, 2017
    risk 0.36cvss 5.5epss 0.02

    ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a crafted xpm file.

  • CVE-2014-9844MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.04

    The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.

  • CVE-2014-9853MedMar 17, 2017
    risk 0.36cvss 5.5epss 0.02

    Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.

  • CVE-2017-6502MedMar 6, 2017
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in ImageMagick 6.9.7. A specially crafted webp file could lead to a file-descriptor leak in libmagickcore (thus, a DoS).

  • CVE-2017-6501MedMar 6, 2017
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could lead to a NULL pointer dereference.

  • CVE-2017-6500MedMar 6, 2017
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buffer over-read.

  • CVE-2017-6499MedMar 6, 2017
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in Magick++ in ImageMagick 6.9.7. A specially crafted file creating a nested exception could lead to a memory leak (thus, a DoS).

  • CVE-2017-6498MedMar 6, 2017
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, thus leading to DoS.

  • CVE-2016-5240MedFeb 27, 2017
    risk 0.36cvss 5.5epss 0.03

    The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.

  • CVE-2016-9773MedFeb 17, 2017
    risk 0.36cvss 5.5epss 0.02

    Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2016-8678MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.02

    The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted file. NOTE: the vendor says "This is a Q64 issue and we do not support Q64."

  • CVE-2016-9298MedJan 27, 2017
    risk 0.36cvss 5.5epss 0.03

    Heap overflow in the WaveletDenoiseImage function in MagickCore/fx.c in ImageMagick before 6.9.6-4 and 7.x before 7.0.3-6 allows remote attackers to cause a denial of service (crash) via a crafted image.

  • CVE-2016-7906MedJan 18, 2017
    risk 0.36cvss 5.5epss 0.02

    magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.

  • CVE-2012-1186MedJun 5, 2012
    risk 0.36cvss 5.5epss 0.02

    Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete…

  • CVE-2012-0248MedJun 5, 2012
    risk 0.36cvss 5.5epss 0.02

    ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.

  • CVE-2026-61857LowJul 11, 2026
    risk 0.35cvss 3.7epss 0.00

    ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.

Page 27 of 42