Vulnerability index

Browse CVEs

492 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Imagemagick MEDIUM 5.5
CVE-2020-27829

A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.

Fix: 7.0.10-45+
Fix from $1,600 2021-03-26
Imagemagick HIGH 7.1
CVE-2020-27752

A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigge…

Fix: 6.9.11-47 / 7.0.9-0+
Fix from $1,950 2020-12-08
Imagemagick MEDIUM 5.5
CVE-2020-27753

There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be triggered by a specially crafted …

Fix: 6.9.10-69 / 7.0.9-0+
Fix from $1,600 2020-12-08
Imagemagick MEDIUM 5.5
CVE-2020-27756

In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculations can lead to divide-by-zero conditions which also lead to undefin…

Fix: 6.9.10-69 / 7.0.9-0+
Fix from $1,600 2020-12-08
Imagemagick MEDIUM 5.5
CVE-2020-25663

A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or heap-buffer-ov…

Fix: 7.0.8-56+
Fix from $1,600 2020-12-08
Imagemagick MEDIUM 5.5
CVE-2020-25667

TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `pr…

Fix: 6.9.10-69 / 7.0.9-0+
Fix from $1,600 2020-12-08
Imagemagick HIGH 7.1
CVE-2020-13902

ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c during TIFF image decoding.

Fix: after 7.0.10-17
Fix from $1,950 2020-06-07
Imagemagick MEDIUM 5.5
CVE-2020-10251

In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c. It can be triggered via an i…

Patch available
Fix from $1,600 2020-03-10
Imagemagick HIGH 7.8
CVE-2014-1947EPSS 7%

Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial …

Fix: after 6.5.4
Fix from $1,950 2020-02-17
Imagemagick MEDIUM 6.5
CVE-2016-7523

coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

Fix: 6.9.4-0+
Fix from $1,600 2020-02-06
Imagemagick MEDIUM 6.5
CVE-2016-7524

coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

Fix: 6.9.4-0+
Fix from $1,600 2020-02-06
Imagemagick CRITICAL 9.8
CVE-2019-19952

In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.

Fix: 7.0.9-7+
Fix from $2,300 2019-12-24
Imagemagick MEDIUM 6.5
CVE-2019-18853

ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, re…

Fix: 7.0.9-0+
Fix from $1,600 2019-11-11
Imagemagick HIGH 8.8
CVE-2019-17547

In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/draw.c has a use-after-free.

Fix: 7.0.8-62+
Fix from $1,950 2019-10-14
Imagemagick HIGH 8.8
CVE-2019-17541

ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager is mishandled in coders/jpeg.c.

Fix: 6.9.10-55 / 7.0.8-55+
Fix from $1,950 2019-10-14
Imagemagick MEDIUM 6.5
CVE-2019-16712

ImageMagick 7.0.8-43 has a memory leak in Huffman2DEncodeImage in coders/ps3.c, as demonstrated by WritePS3Image.

Patch available
Fix from $1,600 2019-09-23
Imagemagick HIGH 8.8
CVE-2019-15140

coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have…

Patch available
Fix from $1,950 2019-08-18
Imagemagick MEDIUM 6.5
CVE-2019-15139

The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (appl…

Patch available
Fix from $1,600 2019-08-18
Imagemagick MEDIUM 6.5
CVE-2019-15141

WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-ba…

Patch available
Fix from $1,600 2019-08-18
Imagemagick MEDIUM 6.5
CVE-2019-14980

In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacke…

Fix: 6.9.10-42 / 7.0.8-42+
Fix from $1,600 2019-08-12
Imagemagick HIGH 8.8
CVE-2019-13391

In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtua…

Patch available
Fix from $1,950 2019-07-07
Imagemagick HIGH 8.8
CVE-2019-13298

ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c er…

Patch available
Fix from $1,950 2019-07-05
Imagemagick HIGH 8.8
CVE-2019-13299

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-accessor.h in GetPixelChannel.

Patch available
Fix from $1,950 2019-07-05
Imagemagick HIGH 8.8
CVE-2019-13302

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/fourier.c in ComplexImages.

Patch available
Fix from $1,950 2019-07-05
Imagemagick HIGH 8.8
CVE-2019-13303

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeImage.

Patch available
Fix from $1,950 2019-07-05
Imagemagick MEDIUM 6.5
CVE-2019-13296

ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a …

Patch available
Fix from $1,600 2019-07-05
Imagemagick HIGH 7.8
CVE-2019-13136

ImageMagick before 7.0.8-50 has an integer overflow vulnerability in the function TIFFSeekCustomStream in coders/tiff.c.

Fix: 7.0.8-50+
Fix from $1,950 2019-07-01
Imagemagick MEDIUM 5.5
CVE-2019-13133

ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c.

Fix: 7.0.8-50+
Fix from $1,600 2019-07-01
Imagemagick MEDIUM 5.5
CVE-2019-13134

ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.

Fix: 7.0.8-50+
Fix from $1,600 2019-07-01
Imagemagick HIGH 7.8
CVE-2019-12977

ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the WriteJP2Image function in coders/jp2.c.

Patch available
Fix from $1,950 2019-06-26