VYPR

Imagemagick

by ImageMagick

Source repositories

CVEs (819)

  • CVE-2026-46522HigJun 10, 2026
    risk 0.52cvss 7.5epss 0.02

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and…

  • CVE-2022-44268MedFeb 6, 2023
    risk 0.52cvss 6.5epss 0.90

    ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).

  • CVE-2023-34153HigMay 30, 2023
    risk 0.51cvss 7.8epss 0.03

    A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.

  • CVE-2022-44267MedFeb 6, 2023
    risk 0.51cvss 6.5epss 0.77

    ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.

  • CVE-2020-29599HigDec 7, 2020
    risk 0.51cvss 7.8epss 0.08

    ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell…

  • CVE-2020-27766HigDec 4, 2020
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long`. This would most likely lead to an impact to…

  • CVE-2020-19667HigNov 20, 2020
    risk 0.51cvss 7.8epss 0.02

    Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.

  • CVE-2019-12979HigJun 26, 2019
    risk 0.51cvss 7.8epss 0.02

    ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c.

  • CVE-2019-12978HigJun 26, 2019
    risk 0.51cvss 7.8epss 0.02

    ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the ReadPANGOImage function in coders/pango.c.

  • CVE-2019-12977HigJun 26, 2019
    risk 0.51cvss 7.8epss 0.02

    ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the WriteJP2Image function in coders/jp2.c.

  • CVE-2014-9825HigMar 30, 2017
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file, a different vulnerability than CVE-2014-9824.

  • CVE-2014-9824HigMar 30, 2017
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file, a different vulnerability than CVE-2014-9825.

  • CVE-2014-9823HigMar 30, 2017
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted palm file, a different vulnerability than CVE-2014-9819.

  • CVE-2014-9822HigMar 30, 2017
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted quantum file.

  • CVE-2014-9821HigMar 30, 2017
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file.

  • CVE-2014-9820HigMar 30, 2017
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted pnm file.

  • CVE-2014-9819HigMar 30, 2017
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted palm file, a different vulnerability than CVE-2014-9823.

  • CVE-2014-9817HigMar 30, 2017
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted pdb file.

  • CVE-2017-5510HigMar 24, 2017
    risk 0.51cvss 7.8epss 0.02

    coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an out-of-bounds write.

  • CVE-2017-5509HigMar 24, 2017
    risk 0.51cvss 7.8epss 0.02

    coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an out-of-bounds write.

Page 6 of 41