cbcvebase.

Debian Imagemagick vulnerabilities

674 known vulnerabilities affecting debian/imagemagick.

Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257

Vulnerabilities

Page 12 of 34
CVE-2017-7619P4HIGHCVSS 7.5fixed in imagemagick 8:6.9.7.4+dfsg-4 (bookworm)2017
CVE-2017-7619 [HIGH] CVE-2017-7619: imagemagick - In ImageMagick 7.0.4-9, an infinite loop can occur because of a floating-point r... In ImageMagick 7.0.4-9, an infinite loop can occur because of a floating-point rounding error in some of the color algorithms. This affects ModulateHSL, ModulateHCL, ModulateHCLp, ModulateHSB, ModulateHSI, ModulateHSV, ModulateHWB, ModulateLCHab, and ModulateLCHuv. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-4) bullseye: resolved (fixed in 8:6.9.7.4+d
debian
CVE-2020-27752P4HIGHCVSS 7.1fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27752 [HIGH] CVE-2020-27752: imagemagick - A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who... A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an impact to data integrity as well. This flaw affects ImageMagick versions prior to 7.0.
debian
CVE-2014-9851P4HIGHCVSS 7.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9851 [HIGH] CVE-2014-9851: imagemagick - ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (applic... ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash). Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2016-10063P4HIGHCVSS 7.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10063 [HIGH] CVE-2016-10063: imagemagick - Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote att... Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file, related to extend validity. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg
debian
CVE-2017-12806P4HIGHCVSS 7.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-12806 [HIGH] CVE-2017-12806: imagemagick - In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the funct... In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function format8BIM, which allows attackers to cause a denial of service. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3) sid: resolved (fixed in 8:6.9.9.34+dfsg-3) trixie: resolved (
debian
CVE-2017-12805P4HIGHCVSS 7.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-12805 [HIGH] CVE-2017-12805: imagemagick - In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the funct... In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function ReadTIFFImage, which allows attackers to cause a denial of service. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3) sid: resolved (fixed in 8:6.9.9.34+dfsg-3) trixie: resolve
debian
CVE-2016-10059P4HIGHCVSS 7.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10059 [HIGH] CVE-2016-10059: imagemagick - Buffer overflow in coders/tiff.c in ImageMagick before 6.9.4-1 allows remote att... Buffer overflow in coders/tiff.c in ImageMagick before 6.9.4-1 allows remote attackers to cause a denial of service (application crash) or have unspecified other impact via a crafted TIFF file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fixe
debian
CVE-2006-2440P4HIGHCVSS 7.5fixed in imagemagick 6:6.2.4.5-0.6 (bookworm)2006
CVE-2006-2440 [HIGH] CVE-2006-2440: imagemagick - Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 mig... Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function. Scope: local bookworm: resolved (fixed in 6:6.2.4.5-0.6) bullseye: resolved (fixed in 6:6.2.4.5-0.6) forky: resolved (fixed i
debian
CVE-2016-10064P4HIGHCVSS 7.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10064 [HIGH] CVE-2016-10064: imagemagick - Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote att... Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fixed in
debian
CVE-2016-10049P4HIGHCVSS 7.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10049 [HIGH] CVE-2016-10049: imagemagick - Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick befo... Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick before 6.9.4-4 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+
debian
CVE-2016-10052P4HIGHCVSS 7.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10052 [HIGH] CVE-2016-10052: imagemagick - Buffer overflow in the WriteProfile function in coders/jpeg.c in ImageMagick bef... Buffer overflow in the WriteProfile function in coders/jpeg.c in ImageMagick before 6.9.5-6 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfs
debian
CVE-2007-1797P4MEDIUMCVSS 9.3fixed in graphicsmagick 1.1.7-15 (bookworm)2007
CVE-2007-1797 [CRITICAL] CVE-2007-1797: graphicsmagick - Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers ... Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues t
debian
CVE-2017-14138P4LOWCVSS 9.8fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-14138 [CRITICAL] CVE-2017-14138: imagemagick - ImageMagick 7.0.6-5 has a memory leak vulnerability in ReadWEBPImage in coders/w... ImageMagick 7.0.6-5 has a memory leak vulnerability in ReadWEBPImage in coders/webp.c because memory is not freed in certain error cases, as demonstrated by VP8 errors. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3) sid: resolved (fixed in 8:6.9.9.34+df
debian
CVE-2017-12666P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-16 (bookworm)2017
CVE-2017-12666 [HIGH] CVE-2017-12666: imagemagick - ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteINLINEImage in coder... ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteINLINEImage in coders/inline.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-16) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-16) forky: resolved (fixed in 8:6.9.7.4+dfsg-16) sid: resolved (fixed in 8:6.9.7.4+dfsg-16) trixie: resolved (fixed in 8:6.9.7.4+dfsg-16)
debian
CVE-2017-12662P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-16 (bookworm)2017
CVE-2017-12662 [HIGH] CVE-2017-12662: imagemagick - ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePDFImage in coders/p... ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePDFImage in coders/pdf.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-16) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-16) forky: resolved (fixed in 8:6.9.7.4+dfsg-16) sid: resolved (fixed in 8:6.9.7.4+dfsg-16) trixie: resolved (fixed in 8:6.9.7.4+dfsg-16)
debian
CVE-2007-0770P4MEDIUMCVSS 5.1fixed in graphicsmagick 1.1.7-12 (bookworm)2007
CVE-2007-0770 [MEDIUM] CVE-2007-0770: graphicsmagick - Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote at... Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456. Scope: local bookworm: resolved (fixed in 1.1.7-
debian
CVE-2026-28494P4HIGHCVSS 7.1fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-28494 [HIGH] CVE-2026-28494: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in st
debian
CVE-2026-27798P4MEDIUMCVSS 4.0fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-27798 [MEDIUM] CVE-2026-27798: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small dimension using the `-wavelet-denoise` operator. Versions 7.1.2-15 and 6.9.13-40 contain a patch. Scope: local bookworm: resolved (fixed in 8:6.
debian
CVE-2016-10065P4HIGHCVSS 7.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10065 [HIGH] CVE-2016-10065: imagemagick - The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows... The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved
debian
CVE-2017-12435P4LOWCVSS 7.5fixed in imagemagick 8:6.9.7.4+dfsg-16 (bookworm)2017
CVE-2017-12435 [HIGH] CVE-2017-12435: imagemagick - In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the funct... In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-16) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-16) forky: resolved (fixed in 8:6.9.7.4+dfsg-16) sid: resolved (fixed in 8:6.9.7.4+dfsg-16)
debian
Debian Imagemagick vulnerabilities | cvebase