Debian Imagemagick vulnerabilities
674 known vulnerabilities affecting debian/imagemagick.
Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257
Vulnerabilities
Page 10 of 34
CVE-2019-12978P3LOWCVSS 7.8fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-12978 [HIGH] CVE-2019-12978: imagemagick - ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the Rea...
ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the ReadPANGOImage function in coders/pango.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in 8:6.9.11.24+dfsg-1)
sid: resolved (fixed in 8:6.9.11.24+dfsg-1)
trixie: resolved (fixed in 8:6.9.11.24+dfsg
debian
CVE-2014-9825P3HIGHCVSS 7.8fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9825 [HIGH] CVE-2014-9825: imagemagick - Heap-based buffer overflow in ImageMagick allows remote attackers to have unspec...
Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file, a different vulnerability than CVE-2014-9824.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6
debian
CVE-2022-32546P3HIGHCVSS 7.8fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2022
CVE-2022-32546 [HIGH] CVE-2022-32546: imagemagick - A vulnerability was found in ImageMagick, causing an outside the range of repres...
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
bullseye:
debian
CVE-2022-32547P3HIGHCVSS 7.8fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2022
CVE-2022-32547 [HIGH] CVE-2022-32547: imagemagick - In ImageMagick, there is load of misaligned address for type 'double', which req...
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.
Scope: lo
debian
CVE-2017-6497P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.7.4+dfsg-2 (bookworm)2017
CVE-2017-6497 [HIGH] CVE-2017-6497: imagemagick - An issue was discovered in ImageMagick 6.9.7. A specially crafted psd file could...
An issue was discovered in ImageMagick 6.9.7. A specially crafted psd file could lead to a NULL pointer dereference (thus, a DoS).
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-2)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-2)
forky: resolved (fixed in 8:6.9.7.4+dfsg-2)
sid: resolved (fixed in 8:6.9.7.4+dfsg-2)
trixie: resolved (fixed in 8:6.9.7.4+dfsg-
debian
CVE-2004-0981P4CRITICALCVSS 10.0fixed in graphicsmagick 1.1.7-1 (bookworm)2004
CVE-2004-0981 [CRITICAL] CVE-2004-0981: graphicsmagick - Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows r...
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
Scope: local
bookworm: resolved (fixed in 1.1.7-1)
bullseye: resolved (fixed in 1.1.7-1)
forky: resolved (fixed in 1.1.7-1)
sid: resolved (fixed in 1.1.7-1)
trixie: resolved (fixed in 1.1.7-1)
debian
CVE-2017-11170P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-12 (bookworm)2017
CVE-2017-11170 [HIGH] CVE-2017-11170: imagemagick - The ReadTGAImage function in coders\tga.c in ImageMagick 7.0.5-6 has a memory le...
The ReadTGAImage function in coders\tga.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via invalid colors data in the header of a TGA or VST file.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-12)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-12)
forky: resolved (fixed in 8:6.9.7.4+dfsg-12)
sid: resolved (fixed
debian
CVE-2017-15015P4LOWCVSS 8.8fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-15015 [HIGH] CVE-2017-15015: imagemagick - ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in PDFDeleg...
ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in PDFDelegateMessage in coders/pdf.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid: resolved (fixed in 8:6.9.9.34+dfsg-3)
trixie: resolved (fixed in 8:6.9.9.34+dfsg-3)
debian
CVE-2015-8895P4HIGHCVSS 7.5fixed in imagemagick 8:6.8.9.9-7 (bookworm)2015
CVE-2015-8895 [HIGH] CVE-2015-8895: imagemagick - Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote...
Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a crafted length value, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-7)
bullseye: resolved (fixed in 8:6.8.9.9-7)
forky: resolved (fixed in 8:6.8.9.9-7)
sid: resolved (fixed in 8:6.
debian
CVE-2005-0005P4HIGHCVSS 7.5fixed in imagemagick 6:6.0.6.2-2.1 (bookworm)2005
CVE-2005-0005 [HIGH] CVE-2005-0005: imagemagick - Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly e...
Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
Scope: local
bookworm: resolved (fixed in 6:6.0.6.2-2.1)
bullseye: resolved (fixed in 6:6.0.6.2-2.1)
forky: resolved (fixed in 6:6.0.6.2-2.1)
sid: resolved (fixed in 6
debian
CVE-2017-14607P4LOWCVSS 8.1fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-14607 [HIGH] CVE-2017-14607: imagemagick - In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage ...
In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed
debian
CVE-2014-9848P4HIGHCVSS 7.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9848 [HIGH] CVE-2014-9848: imagemagick - Memory leak in ImageMagick allows remote attackers to cause a denial of service ...
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2007-1667P4MEDIUMCVSS 9.3fixed in graphicsmagick 1.1.7-14 (bookworm)2007
CVE-2007-1667 [CRITICAL] CVE-2007-1667: graphicsmagick - Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org li...
Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.
Scope: local
bookwo
debian
CVE-2019-12979P4HIGHCVSS 7.8fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-12979 [HIGH] CVE-2019-12979: imagemagick - ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the Syn...
ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in 8:6.9.11.24+dfsg-1)
sid: resolved (fixed in 8:6.9
debian
CVE-2016-10050P4HIGHCVSS 7.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10050 [HIGH] CVE-2016-10050: imagemagick - Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in Image...
Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.
debian
CVE-2017-12418P4LOWCVSS 7.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-12418 [HIGH] CVE-2017-12418: imagemagick - ImageMagick 7.0.6-5 has memory leaks in the parse8BIMW and format8BIM functions ...
ImageMagick 7.0.6-5 has memory leaks in the parse8BIMW and format8BIM functions in coders/meta.c, related to the WriteImage function in MagickCore/constitute.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid: resolved (fixed in 8:6.9.9.34+dfsg-3)
trixie
debian
CVE-2012-1610P3MEDIUMCVSS 6.5fixed in imagemagick 8:6.7.4.0-4 (bookworm)2012
CVE-2012-1610 [MEDIUM] CVE-2012-1610: imagemagick - Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMa...
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
Scope: local
bookworm: resolved (fixed in 8
debian
CVE-2014-9839P4HIGHCVSS 7.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9839 [HIGH] CVE-2014-9839: imagemagick - magick/colormap-private.h in ImageMagick 6.8.9-9 allows remote attackers to caus...
magick/colormap-private.h in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds access).
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2016-10252P4HIGHCVSS 7.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10252 [HIGH] CVE-2016-10252: imagemagick - Memory leak in the IsOptionMember function in MagickCore/option.c in ImageMagick...
Memory leak in the IsOptionMember function in MagickCore/option.c in ImageMagick before 6.9.2-2, as used in ODR-PadEnc and other products, allows attackers to trigger memory consumption.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (fixed in 8:
debian
CVE-2021-40211P4HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-40211 [HIGH] CVE-2021-40211: imagemagick - An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in functio...
An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u2)
forky: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
sid: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
trixie: resolved (fixed in 8:6.9
debian