Debian Imagemagick vulnerabilities
674 known vulnerabilities affecting debian/imagemagick.
Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257
Vulnerabilities
Page 1 of 34
CVE-2016-3714P1HIGHCVSS 8.4KEVPoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3714 [HIGH] CVE-2016-3714: graphicsmagick - The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and...
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: r
debian
CVE-2016-3715P1MEDIUMCVSS 5.5KEVPoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3715 [MEDIUM] CVE-2016-3715: graphicsmagick - The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows...
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3.24-1)
debian
CVE-2016-3718P2MEDIUMCVSS 5.5KEVPoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3718 [MEDIUM] CVE-2016-3718: graphicsmagick - The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7....
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved
debian
CVE-2016-10057P2HIGHCVSS 7.8ExploitedRansomwarefixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10057 [HIGH] CVE-2016-10057: imagemagick - Buffer overflow in the WriteGROUP4Image function in coders/tiff.c in ImageMagick...
Buffer overflow in the WriteGROUP4Image function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2
debian
CVE-2022-44268P2MEDIUMCVSS 6.5PoCfixed in imagemagick 8:6.9.11.60+dfsg-1.6 (bookworm)2022
CVE-2022-44268 [MEDIUM] CVE-2022-44268: imagemagick - ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a P...
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u1)
forky
debian
CVE-2022-44267P3MEDIUMCVSS 6.5PoCfixed in imagemagick 8:6.9.11.60+dfsg-1.6 (bookworm)2022
CVE-2022-44267 [MEDIUM] CVE-2022-44267: imagemagick - ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG im...
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u1)
forky: resolved (fixed in 8:6.9.11.60+dfsg-1.6)
sid: resolved (fixed in 8:6.
debian
CVE-2018-16323P3MEDIUMCVSS 6.5PoCfixed in imagemagick 8:6.9.10.14+dfsg-1 (bookworm)2018
CVE-2018-16323 [MEDIUM] CVE-2018-16323: imagemagick - ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitial...
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.
Scope: local
bookworm: resolved (fixed in 8:6.9.10.14+
debian
CVE-2014-2030P2HIGHCVSS 7.8PoCfixed in imagemagick 8:6.7.7.10+dfsg-1 (bookworm)2014
CVE-2014-2030 [HIGH] CVE-2014-2030: imagemagick - Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in Ima...
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.
Scope: local
bookworm: resolved (fixed in 8:6.7.7.10+dfsg-1)
debian
CVE-2016-5118P2CRITICALCVSS 9.8fixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-5118 [CRITICAL] CVE-2016-5118: graphicsmagick - The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick ...
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolve
debian
CVE-2016-3717P3MEDIUMCVSS 5.5PoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3717 [MEDIUM] CVE-2016-3717: graphicsmagick - The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows rem...
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3.24-1)
debian
CVE-2025-55298P2HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm)2025
CVE-2025-55298 [HIGH] CVE-2025-55298: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to FormatLocaleString without proper sanitization. An attacker can overwrite arbitrary memory regions, e
debian
CVE-2014-1947P3LOWCVSS 7.8PoCfixed in graphicsmagick 1.3.20-1 (bookworm)2014
CVE-2014-1947 [HIGH] CVE-2014-1947: graphicsmagick - Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in Ima...
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.
Scope: local
bookworm: resolved (fixed
debian
CVE-2016-5239P2CRITICALCVSS 9.8fixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-5239 [CRITICAL] CVE-2016-5239: graphicsmagick - The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMag...
The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3.24-1
debian
CVE-2025-53101P2HIGHCVSS 7.4fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm)2025
CVE-2025-53101 [HIGH] CVE-2025-53101: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resul
debian
CVE-2016-3716P3LOWCVSS 3.3PoCfixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-3716 [LOW] CVE-2016-3716: graphicsmagick - The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remot...
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3.24-1)
debian
CVE-2026-23876P3HIGHCVSS 8.1fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u6 (bookworm)2026
CVE-2026-23876 [HIGH] CVE-2026-23876: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads
debian
CVE-2026-25986P3MEDIUMCVSS 5.3fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25986 [MEDIUM] CVE-2026-25986: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2
debian
CVE-2026-25897P3MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25897 [MEDIUM] CVE-2026-25897: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Scope: local
bookworm:
debian
CVE-2026-25968P3HIGHCVSS 7.4fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25968 [HIGH] CVE-2026-25968: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Scope: local
bookworm: r
debian
CVE-2016-5841P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-5841 [CRITICAL] CVE-2016-5841: imagemagick - Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows re...
Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.
debian
1 / 34Next →