cbcvebase.

Debian Imagemagick vulnerabilities

674 known vulnerabilities affecting debian/imagemagick.

Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257

Vulnerabilities

Page 32 of 34
CVE-2014-9836P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9836 [MEDIUM] CVE-2014-9836: imagemagick - ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a c... ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a crafted xpm file. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9838P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9838 [MEDIUM] CVE-2014-9838: imagemagick - magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a denial ... magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (crash). Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2017-6501P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.7.4+dfsg-2 (bookworm)2017
CVE-2017-6501 [MEDIUM] CVE-2017-6501: imagemagick - An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could... An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could lead to a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 8:6.9.7.4+dfsg-2) bullseye: resolved (fixed in 8:6.9.7.4+dfsg-2) forky: resolved (fixed in 8:6.9.7.4+dfsg-2) sid: resolved (fixed in 8:6.9.7.4+dfsg-2) trixie: resolved (fixed in 8:6.9.7.4+dfsg-2)
debian
CVE-2021-4219P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-4219 [MEDIUM] CVE-2021-4219: imagemagick - A flaw was found in ImageMagick. The vulnerability occurs due to improper use of... A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system. Scope: local bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5) bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u2) forky: resolved (fixed in 8:6.9.11.60+dfsg-1.5) sid: resolved
debian
CVE-2023-3745P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2023
CVE-2023-3745 [MEDIUM] CVE-2023-3745: imagemagick - A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() fu... A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service. Scope: local bookworm: resolved (fixed in 8:6.9.1
debian
CVE-2019-12976P4LOWCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-12976 [MEDIUM] CVE-2019-12976: imagemagick - ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pc... ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c. Scope: local bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1) bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1) forky: resolved (fixed in 8:6.9.11.24+dfsg-1) sid: resolved (fixed in 8:6.9.11.24+dfsg-1) trixie: resolved (fixed in 8:6.9.11.24+dfsg-1)
debian
CVE-2019-12975P4LOWCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-12975 [MEDIUM] CVE-2019-12975: imagemagick - ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage functi... ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c. Scope: local bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1) bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1) forky: resolved (fixed in 8:6.9.11.24+dfsg-1) sid: resolved (fixed in 8:6.9.11.24+dfsg-1) trixie: resolved (fixed in 8:6.9.11.24+dfsg-1)
debian
CVE-2016-10068P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.6.5+dfsg-1 (bookworm)2016
CVE-2016-10068 [MEDIUM] CVE-2016-10068: imagemagick - The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cau... The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file. Scope: local bookworm: resolved (fixed in 8:6.9.6.5+dfsg-1) bullseye: resolved (fixed in 8:6.9.6.5+dfsg-1) forky: resolved (fixed in 8:6.9.6.5+dfsg-1) sid: resolved (fixed in 8:6.9.6.5+dfsg-1)
debian
CVE-2016-10069P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10069 [MEDIUM] CVE-2016-10069: imagemagick - coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a de... coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fixed in 8:6.9.6.2+dfsg-2) trix
debian
CVE-2014-9809P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9809 [MEDIUM] CVE-2014-9809: imagemagick - ImageMagick allows remote attackers to cause a denial of service (segmentation f... ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted xwd image. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9808P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9808 [MEDIUM] CVE-2014-9808: imagemagick - ImageMagick allows remote attackers to cause a denial of service (segmentation f... ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted dpc image. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9818P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9818 [MEDIUM] CVE-2014-9818: imagemagick - ImageMagick allows remote attackers to cause a denial of service (out-of-bounds ... ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a malformed sun file. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9806P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9806 [MEDIUM] CVE-2014-9806: imagemagick - ImageMagick allows remote attackers to cause a denial of service (file descripto... ImageMagick allows remote attackers to cause a denial of service (file descriptor consumption) via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2012-3437P4LOWCVSS 4.3fixed in imagemagick 8:6.7.7.10-3 (bookworm)2012
CVE-2012-3437 [MEDIUM] CVE-2012-3437: imagemagick - The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier ... The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation. Scope: local bookworm: resolved (fixed in 8:6.7.7.10-3) bullseye: resolved (fixed i
debian
CVE-2026-30935P4LOWCVSS 4.4fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-30935 [MEDIUM] CVE-2026-30935: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, BilateralBlurImage contains a heap buffer over-read caused by an incorrect conversion. When processing a crafted image with the -bilateral-blur operation an out of bounds read can occur. This vulnerability is fixed in 7.1.2-16. Scope: loca
debian
CVE-2016-10053P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-10053 [MEDIUM] CVE-2016-10053: imagemagick - The WriteTIFFImage function in coders/tiff.c in ImageMagick before 6.9.5-8 allow... The WriteTIFFImage function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fix
debian
CVE-2014-9813P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9813 [MEDIUM] CVE-2014-9813: imagemagick - ImageMagick allows remote attackers to cause a denial of service (application cr... ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted viff file. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2015-8894P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-6 (bookworm)2015
CVE-2015-8894 [MEDIUM] CVE-2015-8894: imagemagick - Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows ... Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows remote attackers to cause a denial of service (application crash) via a crafted tga file. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-6) bullseye: resolved (fixed in 8:6.8.9.9-6) forky: resolved (fixed in 8:6.8.9.9-6) sid: resolved (fixed in 8:6.8.9.9-6) trixie: resolved (fix
debian
CVE-2014-9805P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9805 [MEDIUM] CVE-2014-9805: imagemagick - ImageMagick allows remote attackers to cause a denial of service (segmentation f... ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted pnm file. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2022-3213P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm)2022
CVE-2022-3213 [MEDIUM] CVE-2022-3213: imagemagick - A heap buffer overflow issue was found in ImageMagick. When an application proce... A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service. Scope: local bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u1) bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u3) forky: resolved (fixed in 8:6.9.12.98+dfsg1-2) si
debian
Debian Imagemagick vulnerabilities | cvebase