VYPR

Vendor CVEs

ImageMagick

All CVEs

821 total · sorted by risk
  • CVE-2026-61858LowJul 11, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

  • CVE-2026-56366LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

  • CVE-2026-56374LowJul 8, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or…

  • CVE-2026-56362LowJul 8, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a…

  • CVE-2026-56377LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended…

  • CVE-2026-56363LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application…

  • CVE-2026-56361LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.

  • CVE-2025-68469LowDec 18, 2025
    risk 0.14cvss 3.3epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.

  • CVE-2026-61869LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.

  • CVE-2026-61867LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.

  • CVE-2026-61866LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

  • CVE-2026-61865LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.

  • CVE-2026-61864LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released.

  • CVE-2026-61863LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.

  • CVE-2026-61862LowJul 15, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This…

  • CVE-2026-61870LowJul 11, 2026
    risk 0.12cvss 2.9epss 0.00

    ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

  • CVE-2026-61872LowJul 15, 2026
    risk 0.09cvss 2.5epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes allocated memory not to be released, which can lead to increased memory consumption.

  • CVE-2018-16323MedSep 1, 2018
    risk 0.07cvss 6.5epss 0.49

    ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can…

  • CVE-2026-61464LowJul 15, 2026
    risk 0.05cvss 1.8epss 0.00

    ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.

  • CVE-2026-56364LowJun 30, 2026
    risk 0.05cvss 1.9epss 0.00

    ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files…

  • CVE-2006-4144Aug 15, 2006
    risk 0.04cvss epss 0.11

    Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based…

  • CVE-2005-1275Apr 25, 2005
    risk 0.04cvss epss 0.14

    Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.

  • CVE-2009-1882Jun 2, 2009
    risk 0.01cvss epss 0.07

    Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of…

  • CVE-2025-69204MedDec 30, 2025
    risk 0.00cvss 5.3epss 0.01

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and…

  • CVE-2025-46393LowApr 23, 2025
    risk 0.00cvss 2.9epss 0.00

    In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).

  • CVE-2025-43965LowApr 23, 2025
    risk 0.00cvss 2.9epss 0.01

    In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.

  • CVE-2024-41817HigJul 29, 2024
    risk 0.00cvss 7.0epss 0.01

    ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead…

  • CVE-2023-5341MedNov 19, 2023
    risk 0.00cvss 6.2epss 0.00

    A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.

  • CVE-2023-39978LowAug 8, 2023
    risk 0.00cvss 3.3epss 0.00

    ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.

  • CVE-2023-3745MedJul 24, 2023
    risk 0.00cvss 5.5epss 0.00

    A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to…

  • CVE-2023-3195MedJun 16, 2023
    risk 0.00cvss 5.5epss 0.01

    A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.

  • CVE-2023-34475MedJun 16, 2023
    risk 0.00cvss 5.5epss 0.00

    A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in…

  • CVE-2023-34474MedJun 16, 2023
    risk 0.00cvss 5.5epss 0.00

    A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a…

  • CVE-2023-1906MedApr 12, 2023
    risk 0.00cvss 5.5epss 0.01

    A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting…

  • CVE-2022-3213MedSep 19, 2022
    risk 0.00cvss 5.5epss 0.00

    A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.

  • CVE-2022-1115MedAug 29, 2022
    risk 0.00cvss 5.5epss 0.01

    A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.

  • CVE-2022-0284HigAug 29, 2022
    risk 0.00cvss 7.1epss 0.01

    A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can…

  • CVE-2021-3574LowAug 26, 2022
    risk 0.00cvss 3.3epss 0.00

    A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.

  • CVE-2022-32547HigJun 16, 2022
    risk 0.00cvss 7.8epss 0.01

    In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact…

  • CVE-2022-32546HigJun 16, 2022
    risk 0.00cvss 7.8epss 0.01

    A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to…

  • CVE-2022-32545HigJun 16, 2022
    risk 0.00cvss 7.8epss 0.01

    A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to…

  • CVE-2022-28463HigMay 8, 2022
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.

  • CVE-2021-3610HigFeb 24, 2022
    risk 0.00cvss 7.5epss 0.03

    A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.

  • CVE-2021-3962HigNov 19, 2021
    risk 0.00cvss 7.8epss 0.06

    A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest…

  • CVE-2021-39212MedSep 13, 2021
    risk 0.00cvss 4.4epss 0.00

    ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be read and written when…

  • CVE-2020-27829MedMar 26, 2021
    risk 0.00cvss 5.5epss 0.01

    A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.

  • CVE-2020-27764LowDec 3, 2020
    risk 0.00cvss 3.3epss 0.01

    In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a crafted input file is processed by ImageMagick. Red Hat Product Security marked…

  • CVE-2020-27560LowOct 22, 2020
    risk 0.00cvss 3.3epss 0.02

    ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.

  • CVE-2019-15141MedAug 18, 2019
    risk 0.00cvss 6.5epss 0.02

    WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec,…

  • CVE-2019-15140HigAug 18, 2019
    risk 0.00cvss 8.8epss 0.04

    coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by crafting a Matlab image file that is mishandled in ReadImage in MagickCore/constitute.c.