← Back

Imagemagick

imagemagick

740 CVEs • 3 products

Products (3)

Click to collapse
Toggle

CVEs (740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianImagemagick+1 more
4Debian Linux
ImagemagickOpensuse+1 more
Apr 29, 2026
Jun 5, 2012
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF t...Show more
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.Show less
4Canonical
DebianImagemagick+1 more
4Debian Linux
ImagemagickOpensuse+1 more
Apr 29, 2026
Jun 5, 2012
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image....Show more
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.Show less
4Canonical
DebianImagemagick+1 more
4Debian Linux
ImagemagickOpensuse+1 more
Apr 29, 2026
Jun 5, 2012
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via...Show more
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF IFD0 of an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0247.Show less
5Canonical
DebianImagemagick+2 more
11Debian Linux
Enterprise Linux AusEnterprise Linux Desktop+8 more
Apr 29, 2026
Jun 5, 2012
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
4Canonical
DebianImagemagick+1 more
4Debian Linux
ImagemagickOpensuse+1 more
Apr 29, 2026
Jun 5, 2012
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG fi...Show more
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.Show less
4Canonical
DebianImagemagick+1 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+7 more
Apr 29, 2026
Jun 5, 2012
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
4Canonical
DebianImagemagick+1 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+7 more
Apr 29, 2026
Jun 5, 2012
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0...Show more
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.Show less
1Imagemagick
1Imagemagick
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current w...Show more
Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory.Show less
1Imagemagick
1Imagemagick
Apr 23, 2026
Jun 2, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted T...Show more
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.Show less
1Imagemagick
2Graphicsmagick
Imagemagick
Apr 23, 2026
Mar 5, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denia...Show more
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.Show less
1Imagemagick
2Graphicsmagick
Imagemagick
Apr 23, 2026
Mar 5, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbi...Show more
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.Show less
2Canonical
Imagemagick
2Imagemagick
Ubuntu Linux
Apr 23, 2026
Sep 24, 2007
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow...Show more
Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.Show less
1Imagemagick
1Imagemagick
Apr 23, 2026
Sep 24, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' characte...Show more
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.Show less
1Imagemagick
1Imagemagick
Apr 23, 2026
Sep 24, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-bas...Show more
Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.Show less
1Imagemagick
1Imagemagick
Apr 23, 2026
Sep 24, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlobByte function calls;...Show more
ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlobByte function calls; or (2) an infinite loop in the ReadXCFImage function, related to ReadBlobMSBLong function calls.Show less
1Imagemagick
1Imagemagick
Apr 23, 2026
Apr 2, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) c...Show more
Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.Show less
2Graphicsmagick
Imagemagick
2Graphicsmagick
Imagemagick
Apr 23, 2026
Feb 12, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage...Show more
Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.Show less
3Canonical
DebianImagemagick
3Debian Linux
ImagemagickUbuntu Linux
Apr 23, 2026
Nov 22, 2006
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image.
2Graphicsmagick
Imagemagick
2Graphicsmagick
Imagemagick
Apr 23, 2026
Oct 23, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handl...Show more
Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.Show less
1Imagemagick
1Imagemagick
Apr 16, 2026
Aug 25, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple integer overflows in ImageMagick before 6.2.9 allows user-assisted attackers to execute arbitrary code via crafted Sun Rasterfile (bitmap) images that trigger heap-based buffer overflows.