Debian Imagemagick vulnerabilities
674 known vulnerabilities affecting debian/imagemagick.
Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257
Vulnerabilities
Page 2 of 34
CVE-2016-10144P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.7.4+dfsg-1 (bookworm)2016
CVE-2016-10144 [CRITICAL] CVE-2016-10144: imagemagick - coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by...
coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-1)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-1)
forky: resolved (fixed in 8:6.9.7.4+dfsg-1)
sid: resolved (fixed in 8:6.9.7.4+dfsg-1)
trixie: resolved (fixed in 8:6.9.7.4+dfsg-1)
debian
CVE-2026-25898P3MEDIUMCVSS 6.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25898 [MEDIUM] CVE-2026-25898: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negativ
debian
CVE-2025-57803P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm)2025
CVE-2025-57803 [HIGH] CVE-2025-57803: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images.
debian
CVE-2017-5511P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.7.4+dfsg-1 (bookworm)2017
CVE-2017-5511 [CRITICAL] CVE-2017-5511: imagemagick - coders/psd.c in ImageMagick allows remote attackers to have unspecified impact b...
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-1)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-1)
forky: resolved (fixed in 8:6.9.7.4+dfsg-1)
sid: resolved (fixed in 8:6.9.7.4+dfsg-1)
trixie: resol
debian
CVE-2026-26284P3MEDIUMCVSS 6.5fixed in imagemagick 8:7.1.2.15+dfsg1-1 (forky)2026
CVE-2026-26284 [MEDIUM] CVE-2026-26284: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7
debian
CVE-2025-53014P3LOWCVSS 3.7fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm)2025
CVE-2025-53014 [LOW] CVE-2025-53014: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings containing consecutive percent signs (`%%`). Ver
debian
CVE-2026-25983P3MEDIUMCVSS 5.3fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25983 [MEDIUM] CVE-2026-25983: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The operation element handler replaces and frees the image while the parser continues reading from it, leading to a UAF in ReadBlobString during further parsing. Versions 7
debian
CVE-2026-25987P3MEDIUMCVSS 5.3fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25987 [MEDIUM] CVE-2026-25987: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image decoder when processing crafted MAP files, potentially leading to crashes or unintended memory disclosure during image decoding. Versions 7.1.2-15 and 6.9.13-40 co
debian
CVE-2016-5691P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-5691 [CRITICAL] CVE-2016-5691: imagemagick - The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remot...
The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixel.blue.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid:
debian
CVE-2026-25971P3MEDIUMCVSS 6.2fixed in imagemagick 8:7.1.2.15+dfsg1-1 (forky)2026
CVE-2026-25971 [MEDIUM] CVE-2026-25971: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for circular references between two MSLs, leading to a stack overflow. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 8:7.1.2.15+dfs
debian
CVE-2026-22770P3LOWCVSS 6.5fixed in imagemagick 8:7.1.2.13+dfsg1-1 (forky)2026
CVE-2026-22770 [MEDIUM] CVE-2026-22770: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initialized. This will result in a release of an invalid pointer inside DestroyBilateralTLS
debian
CVE-2006-4144P4MEDIUMCVSS 2.6PoCfixed in graphicsmagick 1.1.7-7 (bookworm)2006
CVE-2006-4144 [LOW] CVE-2006-4144: graphicsmagick - Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2...
Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.1.7-7)
bullseye: resolve
debian
CVE-2012-1185P3HIGHCVSS 8.8fixed in imagemagick 8:6.6.9.7-7 (bookworm)2012
CVE-2012-1185 [HIGH] CVE-2012-1185: imagemagick - Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in I...
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF IFD0 of an image. NOTE: this vulnerability exists because of an incomplete fix for CVE
debian
CVE-2014-9847P3CRITICALCVSS 9.8fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9847 [CRITICAL] CVE-2014-9847: imagemagick - The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspec...
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9826P3CRITICALCVSS 9.8fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9826 [CRITICAL] CVE-2014-9826: imagemagick - ImageMagick allows remote attackers to have unspecified impact via vectors relat...
ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9852P3CRITICALCVSS 9.8fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9852 [CRITICAL] CVE-2014-9852: imagemagick - distribute-cache.c in ImageMagick re-uses objects after they have been destroyed...
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed i
debian
CVE-2005-1275P4MEDIUMCVSS 5.0PoCfixed in imagemagick 6:6.0.6.2-2.3 (bookworm)2005
CVE-2005-1275 [MEDIUM] CVE-2005-1275: imagemagick - Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick...
Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.
Scope: local
bookworm: resolved (fixed in 6:6.0.6.2-2.3)
bullseye: resolved (fixed in 6:6.0.6.2-2.3)
forky: resolved (fixed in 6:6.0.6.2-2.3)
sid: res
debian
CVE-2016-5688P3HIGHCVSS 8.1fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-5688 [HIGH] CVE-2016-5688: imagemagick - The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memo...
The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelInde
debian
CVE-2016-5689P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-5689 [CRITICAL] CVE-2016-5689: imagemagick - The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remot...
The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of NULL pointer checks.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (fixed in 8:6.9.6.2+dfsg-2)
trixie:
debian
CVE-2016-5690P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-5690 [CRITICAL] CVE-2016-5690: imagemagick - The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x be...
The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact via vectors involving the for statement in computing the pixel scaling table.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6
debian