VYPR

Imagemagick

by ImageMagick

Source repositories

CVEs (830)

  • CVE-2019-13296MedJul 5, 2019
    risk 0.00cvss 6.5epss 0.02

    ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a NULL value.

  • CVE-2019-13295HigJul 5, 2019
    risk 0.00cvss 8.8epss 0.03

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.

  • CVE-2019-13137MedJul 1, 2019
    risk 0.00cvss 6.5epss 0.02

    ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.

  • CVE-2019-13136HigJul 1, 2019
    risk 0.00cvss 7.8epss 0.02

    ImageMagick before 7.0.8-50 has an integer overflow vulnerability in the function TIFFSeekCustomStream in coders/tiff.c.

  • CVE-2019-13135HigJul 1, 2019
    risk 0.00cvss 8.8epss 0.03

    ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.

  • CVE-2019-13134MedJul 1, 2019
    risk 0.00cvss 5.5epss 0.01

    ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.

  • CVE-2019-13133MedJul 1, 2019
    risk 0.00cvss 5.5epss 0.01

    ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c.

  • CVE-2019-10131HigApr 30, 2019
    risk 0.00cvss 7.1epss 0.01

    An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.

  • CVE-2019-11472MedApr 23, 2019
    risk 0.00cvss 6.5epss 0.04

    ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (divide-by-zero error) by crafting an XWD image file in which the header indicates neither LSB first nor MSB first.

  • CVE-2019-11470MedApr 23, 2019
    risk 0.00cvss 6.5epss 0.04

    The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for…

  • CVE-2019-10714MedApr 2, 2019
    risk 0.00cvss 6.5epss 0.02

    LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV.

  • CVE-2018-20467MedDec 26, 2018
    risk 0.00cvss 6.5epss 0.03

    In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

  • CVE-2018-16749MedSep 9, 2018
    risk 0.00cvss 6.5epss 0.02

    In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBlob assertion failure and application exit) via a crafted file.

  • CVE-2018-16645MedSep 6, 2018
    risk 0.00cvss 6.5epss 0.04

    There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image file.

  • CVE-2018-16644MedSep 6, 2018
    risk 0.00cvss 6.5epss 0.04

    There is a missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image.

  • CVE-2018-16643MedSep 6, 2018
    risk 0.00cvss 6.5epss 0.03

    The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of the fputc function, which allows remote attackers to cause a denial of service via…

  • CVE-2018-16642MedSep 6, 2018
    risk 0.00cvss 6.5epss 0.04

    The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a denial of service via a crafted image file due to an out-of-bounds write.

  • CVE-2018-16641MedSep 6, 2018
    risk 0.00cvss 6.5epss 0.02

    ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.

  • CVE-2018-16640MedSep 6, 2018
    risk 0.00cvss 6.5epss 0.03

    ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c.

  • CVE-2013-4298Sep 10, 2013
    risk 0.00cvss —epss 0.05

    The ReadGIFImage function in coders/gif.c in ImageMagick before 6.7.8-8 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted comment in a GIF image.