cbcvebase.

Debian Imagemagick vulnerabilities

674 known vulnerabilities affecting debian/imagemagick.

Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257

Vulnerabilities

Page 3 of 34
CVE-2025-57807P3LOWCVSS 3.8fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm)2025
CVE-2025-57807 [LOW] CVE-2025-57807: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, a
debian
CVE-2014-1958P3HIGHCVSS 8.8fixed in imagemagick 8:6.7.7.10+dfsg-1 (bookworm)2014
CVE-2014-1958 [HIGH] CVE-2014-1958: imagemagick - Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick b... Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030. Scope: local bookworm: resolved (fixed in 8:6.7.7.10+dfsg-1) bullseye: resolved (fixed in 8:6.7.7.10+dfsg-1) forky: r
debian
CVE-2026-25965P3HIGHCVSS 8.6fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25965 [HIGH] CVE-2026-25965: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens
debian
CVE-2019-9956P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.10.23+dfsg-2.1 (bookworm)2019
CVE-2019-9956 [HIGH] CVE-2019-9956: imagemagick - In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the funct... In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a denial of service or code execution via a crafted image file. Scope: local bookworm: resolved (fixed in 8:6.9.10.23+dfsg-2.1) bullseye: resolved (fixed in 8:6.9.10.23+dfsg-2.1) forky: resolved (fixed in 8:6.9.10.23+dfs
debian
CVE-2026-28693P3HIGHCVSS 8.1fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-28693 [HIGH] CVE-2026-28693: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 8:7.1.2.16+dfsg1-1) sid: re
debian
CVE-2016-10145P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.7.4+dfsg-1 (bookworm)2016
CVE-2016-10145 [CRITICAL] CVE-2016-10145: imagemagick - Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have ... Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-1) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-1) forky: resolved (fixed in 8:6.9.7.4+dfsg-1) sid: resolved (fixed in 8:6.9.7.4+dfsg-1) trixie: resolved (fixed in 8:6
debian
CVE-2014-9846P3CRITICALCVSS 9.8fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9846 [CRITICAL] CVE-2014-9846: imagemagick - Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.... Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9843P3CRITICALCVSS 9.8fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9843 [CRITICAL] CVE-2014-9843: imagemagick - The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remot... The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2019-19948P3LOWCVSS 9.8fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-19948 [CRITICAL] CVE-2019-19948: imagemagick - In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the functi... In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c. Scope: local bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1) bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1) forky: resolved (fixed in 8:6.9.11.24+dfsg-1) sid: resolved (fixed in 8:6.9.11.24+dfsg-1) trixie: resolved (fixed in 8:6.9.11.24+dfsg-1
debian
CVE-2016-10048P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.5.7+dfsg-1 (bookworm)2016
CVE-2016-10048 [HIGH] CVE-2016-10048: imagemagick - Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allo... Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors. Scope: local bookworm: resolved (fixed in 8:6.9.5.7+dfsg-1) bullseye: resolved (fixed in 8:6.9.5.7+dfsg-1) forky: resolved (fixed in 8:6.9.5.7+dfsg-1) sid: resolved (fixed in 8:6.9.5.7+dfsg-1) trixie: resolved (fi
debian
CVE-2026-24481P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-24481 [HIGH] CVE-2026-24481: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the ex
debian
CVE-2018-14551P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.10.8+dfsg-1 (bookworm)2018
CVE-2018-14551 [CRITICAL] CVE-2018-14551: imagemagick - The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an unini... The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption. Scope: local bookworm: resolved (fixed in 8:6.9.10.8+dfsg-1) bullseye: resolved (fixed in 8:6.9.10.8+dfsg-1) forky: resolved (fixed in 8:6.9.10.8+dfsg-1) sid: resolved (fixed in 8:6.9.10.8+dfsg-1) trixie: resolved (fixed in 8:6.9.1
debian
CVE-2014-9841P3CRITICALCVSS 9.8fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9841 [CRITICAL] CVE-2014-9841: imagemagick - The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote ... The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions." Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolv
debian
CVE-2020-29599P3HIGHCVSS 7.8fixed in imagemagick 8:6.9.11.57+dfsg-1 (bookworm)2020
CVE-2020-29599 [HIGH] CVE-2020-29599: imagemagick - ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authentica... ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c. Scope: local bookworm: resolved (fixed in 8:6.9.11.57+dfsg-
debian
CVE-2026-25794P3LOWCVSS 8.2fixed in imagemagick 8:7.1.2.15+dfsg1-1 (forky)2026
CVE-2026-25794 [HIGH] CVE-2026-25794: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-bit `int`, causing an undersized heap allocation followed by an out-of-bounds write.
debian
CVE-2017-14224P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-14224 [HIGH] CVE-2017-14224: imagemagick - A heap-based buffer overflow in WritePCXImage in coders/pcx.c in ImageMagick 7.0... A heap-based buffer overflow in WritePCXImage in coders/pcx.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service or code execution via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3) sid: resolved (fixed in 8:6.9.
debian
CVE-2012-0247P3HIGHCVSS 8.8fixed in imagemagick 8:6.6.9.7-6 (bookworm)2012
CVE-2012-0247 [HIGH] CVE-2012-0247: imagemagick - ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of ser... ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image. Scope: local bookworm: resolved (fixed in 8:6.6.9.7-6) bullseye: resolved (fixed in 8:6.6.9.7-6) forky: resolved (fixed in 8:6.6.9.7-
debian
CVE-2018-8960P3LOWCVSS 8.8fixed in imagemagick 8:6.9.9.39+dfsg-1 (bookworm)2018
CVE-2018-8960 [HIGH] CVE-2018-8960: imagemagick - The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not... The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, leading to a heap-based buffer over-read. Scope: local bookworm: resolved (fixed in 8:6.9.9.39+dfsg-1) bullseye: resolved (fixed in 8:6.9.9.39+dfsg-1) forky: resolved (fixed in 8:6.9.9.39+dfsg-1) sid: resolved (fixed in 8:6.9.9.39+dfsg-1) trixie: r
debian
CVE-2016-8862P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.6.6+dfsg-1 (bookworm)2016
CVE-2016-8862 [HIGH] CVE-2016-8862: imagemagick - The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.... The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.0.3.3 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. Scope: local bookworm: resolved (fixed in 8:6.9.6.6+dfsg-1) bullseye: resolved (fixed in 8:6.9.6.6+dfsg-1) forky: resolved (fixed in 8:6.9.6.6+dfsg-1) sid: resolved
debian
CVE-2016-8677P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.6.2+dfsg-1 (bookworm)2016
CVE-2016-8677 [HIGH] CVE-2016-8677: imagemagick - The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before ... The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before 7.0.3-1 allows remote attackers to have unspecified impact via a crafted image file, which triggers a memory allocation failure. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-1) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-1) forky: resolved (fixed in 8:6.9.6.2+dfsg-1) sid: r
debian
Debian Imagemagick vulnerabilities | cvebase