VYPR

Imagemagick

by ImageMagick

Source repositories

CVEs (830)

  • CVE-2026-28688MedMar 10, 2026
    risk 0.19cvss 4.0epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-after-free vulnerability exists in the MSL encoder, where a cloned image is destroyed twice. The MSL coder does not support writing…

  • CVE-2026-27799MedFeb 26, 2026
    risk 0.19cvss 4.0epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when…

  • CVE-2026-27798MedFeb 26, 2026
    risk 0.19cvss 4.0epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small dimension using the `-wavelet-denoise` operator. Versions…

  • CVE-2025-68950MedDec 30, 2025
    risk 0.19cvss 4.0epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any situation that allows…

  • CVE-2025-57807LowSep 5, 2025
    risk 0.18cvss 3.8epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and…

  • CVE-2026-93590LowSep 18, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of…

  • CVE-2026-93589LowSep 18, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31…

  • CVE-2026-86421LowSep 7, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service.

  • CVE-2026-86420LowSep 7, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

  • CVE-2026-61871LowJul 15, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

  • CVE-2026-61868LowJul 15, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).

  • CVE-2026-61860LowJul 15, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial…

  • CVE-2026-56373LowJul 10, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

  • CVE-2026-56369LowJun 30, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images.

  • CVE-2026-56365LowJun 30, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.

  • CVE-2026-56368LowJun 24, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.

  • CVE-2026-56376LowJun 23, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

  • CVE-2025-55212LowAug 26, 2025
    risk 0.17cvss 3.7epss 0.01

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (":") to montage -geometry leads GetGeometry() to set width/height to 0. Later,…

  • CVE-2025-53019LowJul 14, 2025
    risk 0.17cvss 3.7epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in a filename template causes a memory…

  • CVE-2025-53014LowJul 14, 2025
    risk 0.17cvss 3.7epss 0.01

    ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory…

Page 35 of 42