Imagemagick
by ImageMagick
Source repositories
CVEs (819)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-28463 | Hig | 0.00 | 7.8 | 0.02 | May 8, 2022 | ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow. | ||
| CVE-2021-3610 | Hig | 0.00 | 7.5 | 0.03 | Feb 24, 2022 | A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault. | ||
| CVE-2021-3962 | Hig | 0.00 | 7.8 | 0.06 | Nov 19, 2021 | A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest… | ||
| CVE-2021-39212 | Med | 0.00 | 4.4 | 0.00 | Sep 13, 2021 | ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be read and written when… | ||
| CVE-2020-27829 | Med | 0.00 | 5.5 | 0.01 | Mar 26, 2021 | A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45. | ||
| CVE-2020-27764 | Low | 0.00 | 3.3 | 0.01 | Dec 3, 2020 | In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a crafted input file is processed by ImageMagick. Red Hat Product Security marked… | ||
| CVE-2020-27560 | Low | 0.00 | 3.3 | 0.02 | Oct 22, 2020 | ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service. | ||
| CVE-2019-15141 | Med | 0.00 | 6.5 | 0.02 | Aug 18, 2019 | WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec,… | ||
| CVE-2019-15140 | Hig | 0.00 | 8.8 | 0.04 | Aug 18, 2019 | coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by crafting a Matlab image file that is mishandled in ReadImage in MagickCore/constitute.c. | ||
| CVE-2019-15139 | Med | 0.00 | 6.5 | 0.04 | Aug 18, 2019 | The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read) in ReadXWDImage in coders/xwd.c by crafting a corrupted XWD image file, a… | ||
| CVE-2019-14981 | Med | 0.00 | 6.5 | 0.03 | Aug 12, 2019 | In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file. | ||
| CVE-2019-14980 | Med | 0.00 | 6.5 | 0.02 | Aug 12, 2019 | In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafted file. | ||
| CVE-2019-13454 | Med | 0.00 | 6.5 | 0.04 | Jul 9, 2019 | ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c. | ||
| CVE-2019-13391 | Hig | 0.00 | 8.8 | 0.03 | Jul 7, 2019 | In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels. | ||
| CVE-2019-13311 | Med | 0.00 | 6.5 | 0.03 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error. | ||
| CVE-2019-13310 | Med | 0.00 | 6.5 | 0.02 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c. | ||
| CVE-2019-13309 | Med | 0.00 | 6.5 | 0.03 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c. | ||
| CVE-2019-13308 | Hig | 0.00 | 8.8 | 0.03 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage. | ||
| CVE-2019-13307 | Hig | 0.00 | 7.8 | 0.02 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows. | ||
| CVE-2019-13306 | Hig | 0.00 | 7.8 | 0.02 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors. |
- risk 0.00cvss 7.8epss 0.02
ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.
- risk 0.00cvss 7.5epss 0.03
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
- risk 0.00cvss 7.8epss 0.06
A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest…
- risk 0.00cvss 4.4epss 0.00
ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be read and written when…
- risk 0.00cvss 5.5epss 0.01
A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.
- risk 0.00cvss 3.3epss 0.01
In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a crafted input file is processed by ImageMagick. Red Hat Product Security marked…
- risk 0.00cvss 3.3epss 0.02
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.
- risk 0.00cvss 6.5epss 0.02
WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec,…
- risk 0.00cvss 8.8epss 0.04
coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by crafting a Matlab image file that is mishandled in ReadImage in MagickCore/constitute.c.
- risk 0.00cvss 6.5epss 0.04
The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read) in ReadXWDImage in coders/xwd.c by crafting a corrupted XWD image file, a…
- risk 0.00cvss 6.5epss 0.03
In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file.
- risk 0.00cvss 6.5epss 0.02
In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafted file.
- risk 0.00cvss 6.5epss 0.04
ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
- risk 0.00cvss 8.8epss 0.03
In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels.
- risk 0.00cvss 6.5epss 0.03
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
- risk 0.00cvss 6.5epss 0.02
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.
- risk 0.00cvss 6.5epss 0.03
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.
- risk 0.00cvss 8.8epss 0.03
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.
- risk 0.00cvss 7.8epss 0.02
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
- risk 0.00cvss 7.8epss 0.02
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.
Page 38 of 41