Debian Imagemagick vulnerabilities
674 known vulnerabilities affecting debian/imagemagick.
Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257
Vulnerabilities
Page 28 of 34
CVE-2017-12566P4LOWCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-16 (bookworm)2017
CVE-2017-12566 [MEDIUM] CVE-2017-12566: imagemagick - In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function Re...
In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadMVGImage in coders/mvg.c, which allows attackers to cause a denial of service, related to the function ReadSVGImage in svg.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-16)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-16)
forky: resolved (fixed in 8:6.9.7.4+dfsg-16)
debian
CVE-2017-14684P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-14684 [MEDIUM] CVE-2017-14684: imagemagick - In ImageMagick 7.0.7-4 Q16, a memory leak vulnerability was found in the functio...
In ImageMagick 7.0.7-4 Q16, a memory leak vulnerability was found in the function ReadVIPSImage in coders/vips.c, which allows attackers to cause a denial of service (memory consumption in ResizeMagickMemory in MagickCore/memory.c) via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
f
debian
CVE-2017-12673P4LOWCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-15 (bookworm)2017
CVE-2017-12673 [MEDIUM] CVE-2017-12673: imagemagick - In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function Re...
In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function ReadOneMNGImage in coders/png.c, which allows attackers to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-15)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-15)
forky: resolved (fixed in 8:6.9.7.4+dfsg-15)
sid: resolved (fixed in 8:6.9.7.4+dfsg-15)
t
debian
CVE-2017-12564P4LOWCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-14 (bookworm)2017
CVE-2017-12564 [MEDIUM] CVE-2017-12564: imagemagick - In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function Re...
In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-14)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-14)
forky: resolved (fixed in 8:6.9.7.4+dfsg-14)
sid: resolved (fixed in 8:6.9.7.4+dfsg-14)
trix
debian
CVE-2017-12672P4LOWCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-14 (bookworm)2017
CVE-2017-12672 [MEDIUM] CVE-2017-12672: imagemagick - In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function Re...
In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-14)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-14)
forky: resolved (fixed in 8:6.9.7.4+dfsg-14)
sid: resolved (fixed in 8:6.9.7.4+dfsg-14)
trix
debian
CVE-2017-12676P4LOWCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-15 (bookworm)2017
CVE-2017-12676 [MEDIUM] CVE-2017-12676: imagemagick - In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function Re...
In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function ReadOneJNGImage in coders/png.c, which allows attackers to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-15)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-15)
forky: resolved (fixed in 8:6.9.7.4+dfsg-15)
sid: resolved (fixed in 8:6.9.7.4+dfsg-15)
t
debian
CVE-2016-9556P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.6.5+dfsg-1 (bookworm)2016
CVE-2016-9556 [MEDIUM] CVE-2016-9556: imagemagick - The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 a...
The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.5+dfsg-1)
bullseye: resolved (fixed in 8:6.9.6.5+dfsg-1)
forky: resolved (fixed in 8:6.9.6.5+dfsg-1)
sid: resolved (fixed in 8:6.9
debian
CVE-2014-8355P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.20-3+deb8u1 (bookworm)2014
CVE-2014-8355 [MEDIUM] CVE-2014-8355: graphicsmagick - PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a...
PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
Scope: local
bookworm: resolved (fixed in 1.3.20-3+deb8u1)
bullseye: resolved (fixed in 1.3.20-3+deb8u1)
forky: resolved (fixed in 1.3.20-3+deb8u1)
sid: resolved (fixed in 1.3.20-3+deb8u1)
trixie: resolved (fixed in 1.3.20-3+deb8u1)
debian
CVE-2014-8562P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-1 (bookworm)2014
CVE-2014-8562 [MEDIUM] CVE-2014-8562: imagemagick - DCM decode in ImageMagick before 6.8.9-9 allows remote attackers to cause a deni...
DCM decode in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-1)
bullseye: resolved (fixed in 8:6.8.9.9-1)
forky: resolved (fixed in 8:6.8.9.9-1)
sid: resolved (fixed in 8:6.8.9.9-1)
trixie: resolved (fixed in 8:6.8.9.9-1)
debian
CVE-2014-9844P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9844 [MEDIUM] CVE-2014-9844: imagemagick - The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote a...
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in
debian
CVE-2017-10995P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2017
CVE-2017-10995 [MEDIUM] CVE-2017-10995: imagemagick - The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote a...
The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (f
debian
CVE-2016-7906P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-7906 [MEDIUM] CVE-2016-7906: imagemagick - magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a den...
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (fixed in 8:6.9.6.2+dfsg-2)
trixie: resolved (fixed in 8:6.9.6.2+df
debian
CVE-2014-9816P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9816 [MEDIUM] CVE-2014-9816: imagemagick - ImageMagick allows remote attackers to cause a denial of service (out-of-bounds ...
ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted viff file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2021-20246P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-20246 [MEDIUM] CVE-2021-20246: imagemagick - A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submit...
A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
bullseye: resolved (fixed i
debian
CVE-2021-20245P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-20245 [MEDIUM] CVE-2021-20245: imagemagick - A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a craf...
A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
bullseye: resolved (fixed in 8:6.9.
debian
CVE-2020-27829P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.57+dfsg-1 (bookworm)2020
CVE-2020-27829 [MEDIUM] CVE-2020-27829: imagemagick - A heap based buffer overflow in coders/tiff.c may result in program crash and de...
A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.57+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.57+dfsg-1)
forky: resolved (fixed in 8:6.9.11.57+dfsg-1)
sid: resolved (fixed in 8:6.9.11.57+dfsg-1)
trixie: resolved (fixed in 8:6.9
debian
CVE-2020-27770P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27770 [MEDIUM] CVE-2020-27770: imagemagick - Due to a missing check for 0 value of `replace_extent`, it is possible for offse...
Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.
Scope: local
bookworm: resolved (fixed in 8:6.9
debian
CVE-2020-27762P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27762 [MEDIUM] CVE-2020-27762: imagemagick - A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a craft...
A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior.
debian
CVE-2020-25665P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-25665 [MEDIUM] CVE-2020-25665: imagemagick - The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMe...
The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 256. This can cause a out-of-bounds read later on in the routine. The patch adds 256 to bytes_per_row in the call to AcquireQuantumMemory(). This could cause impact to reliability. This flaw affects ImageMagick ver
debian
CVE-2020-25674P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-25674 [MEDIUM] CVE-2020-25674: imagemagick - WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an impr...
WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buffer-overflow. This occurs because it is possible for the colormap to have less than 256 valid values but the loop condition will loop 256 times, attempting to pass invalid colormap data to the event logger. The pa
debian