cbcvebase.

Debian Imagemagick vulnerabilities

674 known vulnerabilities affecting debian/imagemagick.

Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257

Vulnerabilities

Page 16 of 34
CVE-2017-12663P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-16 (bookworm)2017
CVE-2017-12663 [HIGH] CVE-2017-12663: imagemagick - ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMAPImage in coders/m... ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMAPImage in coders/map.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-16) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-16) forky: resolved (fixed in 8:6.9.7.4+dfsg-16) sid: resolved (fixed in 8:6.9.7.4+dfsg-16) trixie: resolved (fixed in 8:6.9.7.4+dfsg-16)
debian
CVE-2017-12668P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-16 (bookworm)2017
CVE-2017-12668 [HIGH] CVE-2017-12668: imagemagick - ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePCXImage in coders/p... ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePCXImage in coders/pcx.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-16) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-16) forky: resolved (fixed in 8:6.9.7.4+dfsg-16) sid: resolved (fixed in 8:6.9.7.4+dfsg-16) trixie: resolved (fixed in 8:6.9.7.4+dfsg-16)
debian
CVE-2017-12665P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-16 (bookworm)2017
CVE-2017-12665 [HIGH] CVE-2017-12665: imagemagick - ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePICTImage in coders/... ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePICTImage in coders/pict.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-16) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-16) forky: resolved (fixed in 8:6.9.7.4+dfsg-16) sid: resolved (fixed in 8:6.9.7.4+dfsg-16) trixie: resolved (fixed in 8:6.9.7.4+dfsg-16)
debian
CVE-2017-12664P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-13 (bookworm)2017
CVE-2017-12664 [HIGH] CVE-2017-12664: imagemagick - ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePALMImage in coders/... ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePALMImage in coders/palm.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-13) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-13) forky: resolved (fixed in 8:6.9.7.4+dfsg-13) sid: resolved (fixed in 8:6.9.7.4+dfsg-13) trixie: resolved (fixed in 8:6.9.7.4+dfsg-13)
debian
CVE-2017-12642P4LOWCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-13 (bookworm)2017
CVE-2017-12642 [HIGH] CVE-2017-12642: imagemagick - ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadMPCImage in coders\mp... ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadMPCImage in coders\mpc.c. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-13) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-13) forky: resolved (fixed in 8:6.9.7.4+dfsg-13) sid: resolved (fixed in 8:6.9.7.4+dfsg-13) trixie: resolved (fixed in 8:6.9.7.4+dfsg-13)
debian
CVE-2026-28688P4MEDIUMCVSS 4.0fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-28688 [MEDIUM] CVE-2026-28688: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-after-free vulnerability exists in the MSL encoder, where a cloned image is destroyed twice. The MSL coder does not support writing MSL so the write capability has been removed. This vulnerability is fixed in 7.1.2
debian
CVE-2017-11525P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-12 (bookworm)2017
CVE-2017-11525 [MEDIUM] CVE-2017-11525: imagemagick - The ReadCINImage function in coders/cin.c in ImageMagick before 6.9.9-0 and 7.x ... The ReadCINImage function in coders/cin.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-12) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-12) forky: resolved (fixed in 8:6.9.7.4+dfsg-12) sid: resolved (fixe
debian
CVE-2018-5246P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2018
CVE-2018-5246 [MEDIUM] CVE-2018-5246: imagemagick - In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadPATTERNImage in coder... In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadPATTERNImage in coders/pattern.c. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3) sid: resolved (fixed in 8:6.9.9.34+dfsg-3) trixie: resolved (fixed in 8:6.9.9.34+dfsg-3)
debian
CVE-2016-9559P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.6.5+dfsg-1 (bookworm)2016
CVE-2016-9559 [MEDIUM] CVE-2016-9559: imagemagick - coders/tiff.c in ImageMagick before 7.0.3.7 allows remote attackers to cause a d... coders/tiff.c in ImageMagick before 7.0.3.7 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted image. Scope: local bookworm: resolved (fixed in 8:6.9.6.5+dfsg-1) bullseye: resolved (fixed in 8:6.9.6.5+dfsg-1) forky: resolved (fixed in 8:6.9.6.5+dfsg-1) sid: resolved (fixed in 8:6.9.6.5+dfsg-1) trixie: resolved
debian
CVE-2016-7799P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-7799 [MEDIUM] CVE-2016-7799: imagemagick - MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to ca... MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fixed in 8:6.9.6.2+dfsg-2) trixie: resolved (fixed in
debian
CVE-2019-15139P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-15139 [MEDIUM] CVE-2019-15139: imagemagick - The XWD image (X Window System window dumping file) parsing component in ImageMa... The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read) in ReadXWDImage in coders/xwd.c by crafting a corrupted XWD image file, a different vulnerability than CVE-2019-11472. Scope: local bookworm: resolved (fixed in
debian
CVE-2026-26983P4MEDIUMCVSS 5.3fixed in imagemagick 8:7.1.2.15+dfsg1-1 (forky)2026
CVE-2026-26983 [MEDIUM] CVE-2026-26983: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch. Scope: local bookworm: open bullseye: open forky: resol
debian
CVE-2019-11472P4LOWCVSS 6.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-11472 [MEDIUM] CVE-2019-11472: imagemagick - ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7... ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (divide-by-zero error) by crafting an XWD image file in which the header indicates neither LSB first nor MSB first. Scope: local bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1) bullseye: resolved (fixed in 8:6.9.11.24+dfsg-
debian
CVE-2016-7530P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-7530 [MEDIUM] CVE-2016-7530: imagemagick - The quantum handling code in ImageMagick allows remote attackers to cause a deni... The quantum handling code in ImageMagick allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds write) via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fixed in 8:6.9.6.2+dfsg-2) trixie: res
debian
CVE-2016-7534P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-7534 [MEDIUM] CVE-2016-7534: imagemagick - The generic decoder in ImageMagick allows remote attackers to cause a denial of ... The generic decoder in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fixed in 8:6.9.6.2+dfsg-2) trixie: resolved (fixed in 8:6.9.6.2+dfs
debian
CVE-2018-16645P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.10.14+dfsg-1 (bookworm)2018
CVE-2018-16645 [MEDIUM] CVE-2018-16645: imagemagick - There is an excessive memory allocation issue in the functions ReadBMPImage of c... There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image file. Scope: local bookworm: resolved (fixed in 8:6.9.10.14+dfsg-1) bullseye: resolved (fixed in 8:6.9.10.14+dfsg-1) forky: resolved
debian
CVE-2017-11524P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-12 (bookworm)2017
CVE-2017-11524 [MEDIUM] CVE-2017-11524: imagemagick - The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7... The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-12) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-12) forky: resolved (fixed in 8:6.9.7.4+dfsg-
debian
CVE-2018-20467P4LOWCVSS 6.5fixed in imagemagick 8:6.9.10.23+dfsg-1 (bookworm)2018
CVE-2018-20467 [MEDIUM] CVE-2018-20467: imagemagick - In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an i... In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.10.23+dfsg-1) bullseye: resolved (fixed in 8:6.9.10.23+dfsg-1) forky: res
debian
CVE-2018-16643P4LOWCVSS 6.5fixed in imagemagick 8:6.9.10.8+dfsg-1 (bookworm)2018
CVE-2018-16643 [MEDIUM] CVE-2018-16643: imagemagick - The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCA... The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of the fputc function, which allows remote attackers to cause a denial of service via a crafted image file. Scope: local bookworm: resolved (fixed in 8:6.9.10.8+dfsg-1)
debian
CVE-2016-7515P4MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-7515 [MEDIUM] CVE-2016-7515: imagemagick - The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers... The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fixed in 8:6.9.6.2+dfs
debian
Debian Imagemagick vulnerabilities | cvebase