Vulnerability index

Browse CVEs

492 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2020-27829 A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45. Imagemagick 7.0.10-45+ Fix from $1,6002021-03-26 HIGH 7.1 CVE-2020-27752 A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigge… Imagemagick 6.9.11-47 / 7.0.9-0+ Fix from $1,9502020-12-08 MEDIUM 5.5 CVE-2020-27753 There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be triggered by a specially crafted … Imagemagick 6.9.10-69 / 7.0.9-0+ Fix from $1,6002020-12-08 MEDIUM 5.5 CVE-2020-27756 In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculations can lead to divide-by-zero conditions which also lead to undefin… Imagemagick 6.9.10-69 / 7.0.9-0+ Fix from $1,6002020-12-08 MEDIUM 5.5 CVE-2020-25663 A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or heap-buffer-ov… Imagemagick 7.0.8-56+ Fix from $1,6002020-12-08 MEDIUM 5.5 CVE-2020-25667 TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `pr… Imagemagick 6.9.10-69 / 7.0.9-0+ Fix from $1,6002020-12-08 HIGH 7.1 CVE-2020-13902 ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c during TIFF image decoding. Imagemagick after 7.0.10-17 Fix from $1,9502020-06-07 MEDIUM 5.5 CVE-2020-10251 In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c. It can be triggered via an i… Imagemagick Patch available Fix from $1,6002020-03-10 HIGH 7.8 CVE-2014-1947EPSS 7% Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial … Imagemagick after 6.5.4 Fix from $1,9502020-02-17 MEDIUM 6.5 CVE-2016-7523 coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file. Imagemagick 6.9.4-0+ Fix from $1,6002020-02-06 MEDIUM 6.5 CVE-2016-7524 coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file. Imagemagick 6.9.4-0+ Fix from $1,6002020-02-06 CRITICAL 9.8 CVE-2019-19952 In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage. Imagemagick 7.0.9-7+ Fix from $2,3002019-12-24 MEDIUM 6.5 CVE-2019-18853 ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, re… Imagemagick 7.0.9-0+ Fix from $1,6002019-11-11 HIGH 8.8 CVE-2019-17547 In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/draw.c has a use-after-free. Imagemagick 7.0.8-62+ Fix from $1,9502019-10-14 HIGH 8.8 CVE-2019-17541 ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager is mishandled in coders/jpeg.c. Imagemagick 6.9.10-55 / 7.0.8-55+ Fix from $1,9502019-10-14 MEDIUM 6.5 CVE-2019-16712 ImageMagick 7.0.8-43 has a memory leak in Huffman2DEncodeImage in coders/ps3.c, as demonstrated by WritePS3Image. Imagemagick Patch available Fix from $1,6002019-09-23 HIGH 8.8 CVE-2019-15140 coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have… Imagemagick Patch available Fix from $1,9502019-08-18 MEDIUM 6.5 CVE-2019-15139 The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (appl… Imagemagick Patch available Fix from $1,6002019-08-18 MEDIUM 6.5 CVE-2019-15141 WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-ba… Imagemagick Patch available Fix from $1,6002019-08-18 MEDIUM 6.5 CVE-2019-14980 In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacke… Imagemagick 6.9.10-42 / 7.0.8-42+ Fix from $1,6002019-08-12 HIGH 8.8 CVE-2019-13391 In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtua… Imagemagick Patch available Fix from $1,9502019-07-07 HIGH 8.8 CVE-2019-13298 ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c er… Imagemagick Patch available Fix from $1,9502019-07-05 HIGH 8.8 CVE-2019-13299 ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-accessor.h in GetPixelChannel. Imagemagick Patch available Fix from $1,9502019-07-05 HIGH 8.8 CVE-2019-13302 ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/fourier.c in ComplexImages. Imagemagick Patch available Fix from $1,9502019-07-05 HIGH 8.8 CVE-2019-13303 ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeImage. Imagemagick Patch available Fix from $1,9502019-07-05 MEDIUM 6.5 CVE-2019-13296 ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a … Imagemagick Patch available Fix from $1,6002019-07-05 HIGH 7.8 CVE-2019-13136 ImageMagick before 7.0.8-50 has an integer overflow vulnerability in the function TIFFSeekCustomStream in coders/tiff.c. Imagemagick 7.0.8-50+ Fix from $1,9502019-07-01 MEDIUM 5.5 CVE-2019-13133 ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c. Imagemagick 7.0.8-50+ Fix from $1,6002019-07-01 MEDIUM 5.5 CVE-2019-13134 ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c. Imagemagick 7.0.8-50+ Fix from $1,6002019-07-01 HIGH 7.8 CVE-2019-12977 ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the WriteJP2Image function in coders/jp2.c. Imagemagick Patch available Fix from $1,9502019-06-26