VYPR

Imagemagick

by ImageMagick

Source repositories

CVEs (830)

  • CVE-2026-93587LowSep 18, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource limit, which can result in extra memory…

  • CVE-2026-86425LowSep 7, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).

  • CVE-2026-86423LowSep 7, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service).

  • CVE-2026-86422LowSep 7, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file…

  • CVE-2026-66011LowJul 25, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

  • CVE-2026-61859LowJul 15, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

  • CVE-2026-56375LowJul 15, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service.

  • CVE-2026-61858LowJul 11, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

  • CVE-2026-56366LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

  • CVE-2026-56374LowJul 8, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or…

  • CVE-2026-56362LowJul 8, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a…

  • CVE-2026-56377LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended…

  • CVE-2026-56363LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application…

  • CVE-2026-56361LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.

  • CVE-2025-68469LowDec 18, 2025
    risk 0.14cvss 3.3epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.

  • CVE-2026-93588LowSep 18, 2026
    risk 0.13cvss 3.1epss 0.00

    ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NULL pointer is dereferenced, which can lead…

  • CVE-2026-93586LowSep 18, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is…

  • CVE-2026-61869LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.

  • CVE-2026-61867LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.

  • CVE-2026-61866LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

Page 36 of 42