← Back

Imagemagick

imagemagick

740 CVEs • 3 products

Products (3)

Click to collapse
Toggle

CVEs (740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Imagemagick
2Debian Linux
Imagemagick
May 13, 2026
Jul 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via JPEG data that is too short.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
coders/mpc.c in ImageMagick before 7.0.6-1 does not enable seekable streams and thus cannot validate blob sizes, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified...Show more
coders/mpc.c in ImageMagick before 7.0.6-1 does not enable seekable streams and thus cannot validate blob sizes, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an image received from stdin.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Jul 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadSCREENSHOTImage function in coders/screenshot.c in ImageMagick before 7.0.6-1 has memory leaks, causing denial of service.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 19, 2017
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU exhaustion via a crafted PES file.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadRLEImage function in coders\rle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value.
3Canonical
DebianImagemagick
3Debian Linux
ImagemagickUbuntu Linux
May 13, 2026
Jul 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 13, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The read_user_chunk_callback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulnerabilities via crafted PNG files.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 12, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted DPX file, related to lack of an EOF check.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 11, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The ReadTGAImage function in coders\tga.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via invalid colors data in the header of a TGA or VST file.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 10, 2017
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
The ReadXWDImage function in coders\xwd.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted length (number of color-map entries) field in the header of an XWD file.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 10, 2017
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 7, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 5, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a cr...Show more
In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Jun 7, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function LockSemaphoreInfo, which allows attackers to cause a denial of service via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Jun 7, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Jun 7, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Jun 5, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPSDChannel in coders/psd.c, which allows attackers to cause a denial of service via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Jun 5, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to cause a denial of service via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Jun 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick 7.0.5-5, the ReadMPCImage function in mpc.c allows attackers to cause a denial of service (memory leak) via a crafted file.