Debian Imagemagick vulnerabilities
674 known vulnerabilities affecting debian/imagemagick.
Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257
Vulnerabilities
Page 32 of 34
CVE-2014-9836P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9836 [MEDIUM] CVE-2014-9836: imagemagick - ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a c...
ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a crafted xpm file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9838P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9838 [MEDIUM] CVE-2014-9838: imagemagick - magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a denial ...
magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (crash).
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2017-6501P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.7.4+dfsg-2 (bookworm)2017
CVE-2017-6501 [MEDIUM] CVE-2017-6501: imagemagick - An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could...
An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could lead to a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-2)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-2)
forky: resolved (fixed in 8:6.9.7.4+dfsg-2)
sid: resolved (fixed in 8:6.9.7.4+dfsg-2)
trixie: resolved (fixed in 8:6.9.7.4+dfsg-2)
debian
CVE-2021-4219P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-4219 [MEDIUM] CVE-2021-4219: imagemagick - A flaw was found in ImageMagick. The vulnerability occurs due to improper use of...
A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u2)
forky: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
sid: resolved
debian
CVE-2023-3745P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2023
CVE-2023-3745 [MEDIUM] CVE-2023-3745: imagemagick - A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() fu...
A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 8:6.9.1
debian
CVE-2019-12976P4LOWCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-12976 [MEDIUM] CVE-2019-12976: imagemagick - ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pc...
ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in 8:6.9.11.24+dfsg-1)
sid: resolved (fixed in 8:6.9.11.24+dfsg-1)
trixie: resolved (fixed in 8:6.9.11.24+dfsg-1)
debian
CVE-2019-12975P4LOWCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-12975 [MEDIUM] CVE-2019-12975: imagemagick - ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage functi...
ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in 8:6.9.11.24+dfsg-1)
sid: resolved (fixed in 8:6.9.11.24+dfsg-1)
trixie: resolved (fixed in 8:6.9.11.24+dfsg-1)
debian
CVE-2016-10068P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.6.5+dfsg-1 (bookworm)2016
CVE-2016-10068 [MEDIUM] CVE-2016-10068: imagemagick - The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cau...
The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.5+dfsg-1)
bullseye: resolved (fixed in 8:6.9.6.5+dfsg-1)
forky: resolved (fixed in 8:6.9.6.5+dfsg-1)
sid: resolved (fixed in 8:6.9.6.5+dfsg-1)
debian
CVE-2016-10069P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10069 [MEDIUM] CVE-2016-10069: imagemagick - coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a de...
coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (fixed in 8:6.9.6.2+dfsg-2)
trix
debian
CVE-2014-9809P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9809 [MEDIUM] CVE-2014-9809: imagemagick - ImageMagick allows remote attackers to cause a denial of service (segmentation f...
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted xwd image.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9808P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9808 [MEDIUM] CVE-2014-9808: imagemagick - ImageMagick allows remote attackers to cause a denial of service (segmentation f...
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted dpc image.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9818P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9818 [MEDIUM] CVE-2014-9818: imagemagick - ImageMagick allows remote attackers to cause a denial of service (out-of-bounds ...
ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a malformed sun file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9806P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9806 [MEDIUM] CVE-2014-9806: imagemagick - ImageMagick allows remote attackers to cause a denial of service (file descripto...
ImageMagick allows remote attackers to cause a denial of service (file descriptor consumption) via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2012-3437P4LOWCVSS 4.3fixed in imagemagick 8:6.7.7.10-3 (bookworm)2012
CVE-2012-3437 [MEDIUM] CVE-2012-3437: imagemagick - The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier ...
The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.
Scope: local
bookworm: resolved (fixed in 8:6.7.7.10-3)
bullseye: resolved (fixed i
debian
CVE-2026-30935P4LOWCVSS 4.4fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-30935 [MEDIUM] CVE-2026-30935: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, BilateralBlurImage contains a heap buffer over-read caused by an incorrect conversion. When processing a crafted image with the -bilateral-blur operation an out of bounds read can occur. This vulnerability is fixed in 7.1.2-16.
Scope: loca
debian
CVE-2016-10053P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10053 [MEDIUM] CVE-2016-10053: imagemagick - The WriteTIFFImage function in coders/tiff.c in ImageMagick before 6.9.5-8 allow...
The WriteTIFFImage function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (fix
debian
CVE-2014-9813P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9813 [MEDIUM] CVE-2014-9813: imagemagick - ImageMagick allows remote attackers to cause a denial of service (application cr...
ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted viff file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2015-8894P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-6 (bookworm)2015
CVE-2015-8894 [MEDIUM] CVE-2015-8894: imagemagick - Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows ...
Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows remote attackers to cause a denial of service (application crash) via a crafted tga file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-6)
bullseye: resolved (fixed in 8:6.8.9.9-6)
forky: resolved (fixed in 8:6.8.9.9-6)
sid: resolved (fixed in 8:6.8.9.9-6)
trixie: resolved (fix
debian
CVE-2014-9805P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9805 [MEDIUM] CVE-2014-9805: imagemagick - ImageMagick allows remote attackers to cause a denial of service (segmentation f...
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted pnm file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2022-3213P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm)2022
CVE-2022-3213 [MEDIUM] CVE-2022-3213: imagemagick - A heap buffer overflow issue was found in ImageMagick. When an application proce...
A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u1)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u3)
forky: resolved (fixed in 8:6.9.12.98+dfsg1-2)
si
debian