VYPR

Imagemagick

by ImageMagick

Source repositories

CVEs (819)

  • CVE-2026-61857LowJul 11, 2026
    risk 0.35cvss 3.7epss 0.00

    ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.

  • CVE-2026-53466MedJul 1, 2026
    risk 0.35cvss 6.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash.…

  • CVE-2026-28493MedMar 10, 2026
    risk 0.35cvss 6.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted…

  • CVE-2026-26284MedFeb 24, 2026
    risk 0.35cvss 6.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that…

  • CVE-2026-25982MedFeb 24, 2026
    risk 0.35cvss 6.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap out-of-bounds read vulnerability exists in the `coders/dcm.c` module. When processing DICOM files with a specific configuration, the…

  • CVE-2026-25898MedFeb 24, 2026
    risk 0.35cvss 6.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In…

  • CVE-2026-25897MedFeb 24, 2026
    risk 0.35cvss 6.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds…

  • CVE-2026-23952MedJan 22, 2026
    risk 0.35cvss 6.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can…

  • CVE-2026-22770MedJan 20, 2026
    risk 0.35cvss 6.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly…

  • CVE-2016-7524MedFeb 6, 2020
    risk 0.35cvss 6.5epss 0.02

    coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

  • CVE-2016-7523MedFeb 6, 2020
    risk 0.35cvss 6.5epss 0.03

    coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

  • CVE-2019-18853MedNov 11, 2019
    risk 0.35cvss 6.5epss 0.01

    ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.

  • CVE-2018-18016MedOct 5, 2018
    risk 0.35cvss 6.5epss 0.02

    ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePCXImage in coders/pcx.c.

  • CVE-2018-6405MedJan 30, 2018
    risk 0.35cvss 6.5epss 0.02

    In the ReadDCMImage function in coders/dcm.c in ImageMagick before 7.0.7-23, each redmap, greenmap, and bluemap variable can be overwritten by a new pointer. The previous pointer is lost, which leads to a memory leak. This allows remote attackers to cause a denial of service.

  • CVE-2017-17504MedDec 11, 2017
    risk 0.35cvss 6.5epss 0.02

    ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage.

  • CVE-2015-8958MedApr 20, 2017
    risk 0.35cvss 6.5epss 0.03

    coders/sun.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted SUN file.

  • CVE-2015-8957MedApr 20, 2017
    risk 0.35cvss 6.5epss 0.03

    Buffer overflow in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (application crash) via a crafted SUN file.

  • CVE-2014-9907MedApr 19, 2017
    risk 0.35cvss 6.5epss 0.02

    coders/dds.c in ImageMagick allows remote attackers to cause a denial of service via a crafted DDS file.

  • CVE-2015-8896MedMar 15, 2017
    risk 0.35cvss 6.5epss 0.03

    Integer truncation issue in coders/pict.c in ImageMagick before 7.0.5-0 allows remote attackers to cause a denial of service (application crash) via a crafted .pict file.

  • CVE-2016-10061MedMar 3, 2017
    risk 0.35cvss 6.5epss 0.03

    The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.

Page 28 of 41