cbcvebase.

Debian Imagemagick vulnerabilities

674 known vulnerabilities affecting debian/imagemagick.

Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257

Vulnerabilities

Page 15 of 34
CVE-2014-8561P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.8.9.9-1 (bookworm)2014
CVE-2014-8561 [MEDIUM] CVE-2014-8561: imagemagick - imagemagick 6.8.9.6 has remote DOS via infinite loop imagemagick 6.8.9.6 has remote DOS via infinite loop Scope: local bookworm: resolved (fixed in 8:6.8.9.9-1) bullseye: resolved (fixed in 8:6.8.9.9-1) forky: resolved (fixed in 8:6.8.9.9-1) sid: resolved (fixed in 8:6.8.9.9-1) trixie: resolved (fixed in 8:6.8.9.9-1)
debian
CVE-2004-0827P4HIGHCVSS 7.5fixed in imagemagick 5:6.0.7.1-1 (bookworm)2004
CVE-2004-0827 [HIGH] CVE-2004-0827: imagemagick - Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, ... Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files. Scope: local bookworm: resolved (fixed in 5:6.0.7.1-1) bullseye: resolved (fixed in 5:6.0.7.1-1) forky:
debian
CVE-2017-13758P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-13758 [MEDIUM] CVE-2017-13758: imagemagick - In ImageMagick 7.0.6-10, there is a heap-based buffer overflow in the TracePoint... In ImageMagick 7.0.6-10, there is a heap-based buffer overflow in the TracePoint() function in MagickCore/draw.c. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3) sid: resolved (fixed in 8:6.9.9.34+dfsg-3) trixie: resolved (fixed in 8:6.9.9.34+dfsg-3)
debian
CVE-2017-7942P4LOWCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-6 (bookworm)2017
CVE-2017-7942 [MEDIUM] CVE-2017-7942: imagemagick - The ReadAVSImage function in avs.c in ImageMagick 7.0.5-4 allows remote attacker... The ReadAVSImage function in avs.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-6) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-6) forky: resolved (fixed in 8:6.9.7.4+dfsg-6) sid: resolved (fixed in 8:6.9.7.4+dfsg-6) trixie: resolved (fixed in 8
debian
CVE-2017-12667P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-14 (bookworm)2017
CVE-2017-12667 [HIGH] CVE-2017-12667: imagemagick - ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadMATImage in coders\ma... ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadMATImage in coders\mat.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-14) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-14) forky: resolved (fixed in 8:6.9.7.4+dfsg-14) sid: resolved (fixed in 8:6.9.7.4+dfsg-14) trixie: resolved (fixed in 8:6.9.7.4+dfsg-14)
debian
CVE-2017-12641P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-15 (bookworm)2017
CVE-2017-12641 [HIGH] CVE-2017-12641: imagemagick - ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadOneJNGImage in coders... ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadOneJNGImage in coders\png.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-15) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-15) forky: resolved (fixed in 8:6.9.7.4+dfsg-15) sid: resolved (fixed in 8:6.9.7.4+dfsg-15) trixie: resolved (fixed in 8:6.9.7.4+dfsg-15)
debian
CVE-2026-30937P4MEDIUMCVSS 6.8fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-30937 [MEDIUM] CVE-2026-30937: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur. This vulnerability is fixed in 7.1.
debian
CVE-2005-0397P4HIGHCVSS 7.5fixed in graphicsmagick 1.1.7-1 (bookworm)2005
CVE-2005-0397 [HIGH] CVE-2005-0397: graphicsmagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag... Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications. Scope: local bookworm: resolved (fixed in
debian
CVE-2018-5357P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2018
CVE-2018-5357 [MEDIUM] CVE-2018-5357: imagemagick - ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders... ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3) sid: resolved (fixed in 8:6.9.9.34+dfsg-3) trixie: resolved (fixed in 8:6.9.9.34+dfsg-3)
debian
CVE-2016-7538P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-7538 [MEDIUM] CVE-2016-7538: imagemagick - coders/psd.c in ImageMagick allows remote attackers to cause a denial of service... coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fixed in 8:6.9.6.2+dfsg-2) trixie: resolved (fixed in 8:6.9.6.2+dfsg-2)
debian
CVE-2026-25638P4MEDIUMCVSS 5.3fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25638 [MEDIUM] CVE-2026-25638: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocated. But the function returns early without releasing these allocated resources. Versions 7.1.2-15 and 6.9.13-40 c
debian
CVE-2026-28687P4MEDIUMCVSS 5.3fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-28687 [MEDIUM] CVE-2026-28687: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. Scope: local bookworm: open
debian
CVE-2019-10131P4HIGHCVSS 7.1fixed in imagemagick 8:6.9.10.2+dfsg-2 (bookworm)2019
CVE-2019-10131 [HIGH] CVE-2019-10131: imagemagick - An off-by-one read vulnerability was discovered in ImageMagick before version 7.... An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program. Scope: local bookworm: resolved (fixed in 8:6.9.10.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.10.2+dfsg-2) forky: resolved
debian
CVE-2017-11639P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-15 (bookworm)2017
CVE-2017-11639 [MEDIUM] CVE-2017-11639: imagemagick - When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a h... When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteCIPImage() function in coders/cip.c, related to the GetPixelLuma function in MagickCore/pixel-accessor.h. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-15) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-15) forky: resolved (fixed in 8:
debian
CVE-2017-18273P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-18273 [MEDIUM] CVE-2017-18273: imagemagick - In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability wa... In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fix
debian
CVE-2017-13768P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-13768 [MEDIUM] CVE-2017-13768: imagemagick - Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c ... Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker to perform denial of service by sending a crafted image file. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3) sid: resolved (
debian
CVE-2017-14341P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-14341 [MEDIUM] CVE-2017-14341: imagemagick - ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg... ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3) sid: resolved (fixed in 8:6.9.9.34+dfsg-3) trixie: resolved (fixed in 8
debian
CVE-2017-14173P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-14173 [MEDIUM] CVE-2017-14173: imagemagick - In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integ... In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition operation "GetQuantumRange(depth)+1" when "depth" is large, producing a smaller value than expected. As a result, an infinite loop would occur for a crafted TXT file that claims a very large "max_value" value. Scope: local bookworm: resolved
debian
CVE-2017-11446P4LOWCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-13 (bookworm)2017
CVE-2017-11446 [MEDIUM] CVE-2017-11446: imagemagick - The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite... The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU exhaustion via a crafted PES file. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-13) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-13) forky: resolved (fixed in 8:6.9.7.4+dfsg-13) sid: resolved (fixed in 8:6.9.7.4+dfsg-13) trixie: res
debian
CVE-2017-12669P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-16 (bookworm)2017
CVE-2017-12669 [HIGH] CVE-2017-12669: imagemagick - ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteCALSImage in coders/... ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteCALSImage in coders/cals.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-16) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-16) forky: resolved (fixed in 8:6.9.7.4+dfsg-16) sid: resolved (fixed in 8:6.9.7.4+dfsg-16) trixie: resolved (fixed in 8:6.9.7.4+dfsg-16)
debian
Debian Imagemagick vulnerabilities | cvebase