Vulnerability index

Browse CVEs

492 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Imagemagick HIGH 7.8
CVE-2019-12978

ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the ReadPANGOImage function in coders/pango.c.

Patch available
Fix from $1,950 2019-06-26
Imagemagick MEDIUM 5.5
CVE-2019-12974

A NULL pointer dereference in the function ReadPANGOImage in coders/pango.c and the function ReadVIDImage in coders/vid.c in ImageMagick 7.0.8-34 all…

Patch available
Fix from $1,600 2019-06-26
Imagemagick HIGH 7.5
CVE-2017-12805

In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function ReadTIFFImage, which allows attackers to cause a denial of servic…

No fix yet
Fix from $1,950 2019-05-09
Imagemagick HIGH 7.5
CVE-2017-12806

In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function format8BIM, which allows attackers to cause a denial of service.

No fix yet
Fix from $1,950 2019-05-09
Imagemagick HIGH 8.1
CVE-2019-11597

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to caus…

No fix yet
Fix from $1,950 2019-04-29
Imagemagick HIGH 8.1
CVE-2019-11598

In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which allows an attacker to cause …

Patch available
Fix from $1,950 2019-04-29
Imagemagick MEDIUM 6.5
CVE-2019-11470

The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by craftin…

Patch available
Fix from $1,600 2019-04-23
Imagemagick MEDIUM 6.5
CVE-2019-11472

ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (divide-by-…

Patch available
Fix from $1,600 2019-04-23
Imagemagick MEDIUM 6.5
CVE-2019-10714

LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV.

Fix: 6.9.10-32 / 7.0.8-32+
Fix from $1,600 2019-04-02
Imagemagick MEDIUM 6.5
CVE-2018-18023

In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the SVGStripString function of coders/svg.c, which allows attackers to cause a…

Patch available
Fix from $1,600 2018-10-07
Imagemagick MEDIUM 6.5
CVE-2018-18024

In ImageMagick 7.0.8-13 Q16, there is an infinite loop in the ReadBMPImage function of the coders/bmp.c file. Remote attackers could leverage this vu…

Patch available
Fix from $1,600 2018-10-07
Imagemagick MEDIUM 6.5
CVE-2018-18016

ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePCXImage in coders/pcx.c.

Patch available
Fix from $1,600 2018-10-05
Imagemagick MEDIUM 6.5
CVE-2018-17965

ImageMagick 7.0.7-28 has a memory leak vulnerability in WriteSGIImage in coders/sgi.c.

Patch available
Fix from $1,600 2018-10-03
Imagemagick MEDIUM 6.5
CVE-2018-17966

ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c.

Patch available
Fix from $1,600 2018-10-03
Imagemagick MEDIUM 6.5
CVE-2018-17967

ImageMagick 7.0.7-28 has a memory leak vulnerability in ReadBGRImage in coders/bgr.c.

Patch available
Fix from $1,600 2018-10-03
Imagemagick MEDIUM 6.5
CVE-2018-16641

ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.

Patch available
Fix from $1,600 2018-09-06
Imagemagick HIGH 8.8
CVE-2018-16412

ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function.

No fix yet
Fix from $1,950 2018-09-03
Imagemagick HIGH 8.8
CVE-2018-16413

ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the MagickCore/quantum-private.h PushShortPixel function when called from the coders/ps…

No fix yet
Fix from $1,950 2018-09-03
Imagemagick CRITICAL 9.8
CVE-2018-16328

In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.

Fix: 7.0.8-8+
Fix from $2,300 2018-09-01
Imagemagick CRITICAL 9.8
CVE-2018-16329

In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the GetMagickProperty function in MagickCore/property.c.

Fix: 7.0.8-8+
Fix from $2,300 2018-09-01
Imagemagick MEDIUM 6.5
CVE-2018-15607EPSS 5%

In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result i…

No fix yet
Fix from $1,600 2018-08-21
Imagemagick HIGH 8.8
CVE-2018-11624

In ImageMagick 7.0.7-36 Q16, the ReadMATImage function in coders/mat.c allows attackers to cause a use after free via a crafted file.

Mitigation only
Fix from $1,950 2018-05-31
Imagemagick MEDIUM 6.5
CVE-2017-18272

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-25, there is a use-after-free in ReadOneMNGImage in coders/png.c, which allows attackers to cause a denial…

Fix: 7.0.7-21+
Fix from $1,600 2018-05-18
Imagemagick MEDIUM 6.5
CVE-2018-11251

In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows attackers to caus…

Fix: 7.0.7-21+
Fix from $1,600 2018-05-18
Imagemagick HIGH 8.8
CVE-2018-9135

In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c.

No fix yet
Fix from $1,950 2018-03-30
Imagemagick MEDIUM 6.5
CVE-2017-18250

An issue was discovered in ImageMagick 7.0.7. A NULL pointer dereference vulnerability was found in the function LogOpenCLBuildFailure in MagickCore/…

Patch available
Fix from $1,600 2018-03-27
Imagemagick MEDIUM 6.5
CVE-2017-18253

An issue was discovered in ImageMagick 7.0.7. A NULL pointer dereference vulnerability was found in the function LoadOpenCLDevices in MagickCore/open…

Patch available
Fix from $1,600 2018-03-27
Imagemagick CRITICAL 9.8
CVE-2017-18210

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function BenchmarkOpenCLDevices in MagickCore/opencl.c because a memo…

Patch available
Fix from $2,300 2018-03-01
Imagemagick MEDIUM 6.5
CVE-2018-7470

An issue was discovered in ImageMagick 7.0.7-22 Q16. The IsWEBPImageLossless function in coders/webp.c allows attackers to cause a denial of service …

No fix yet
Fix from $1,600 2018-02-25
Imagemagick MEDIUM 6.5
CVE-2018-6930

A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0.7-22 allows a remote attacke…

Mitigation only
Fix from $1,600 2018-02-13