cbcvebase.

Debian Imagemagick vulnerabilities

674 known vulnerabilities affecting debian/imagemagick.

Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257

Vulnerabilities

Page 33 of 34
CVE-2014-9815P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9815 [MEDIUM] CVE-2014-9815: imagemagick - ImageMagick allows remote attackers to cause a denial of service (application cr... ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted wpg file. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2014-9810P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9810 [MEDIUM] CVE-2014-9810: imagemagick - The dpx file handler in ImageMagick allows remote attackers to cause a denial of... The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.
debian
CVE-2014-9811P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9811 [MEDIUM] CVE-2014-9811: imagemagick - The xwd file handler in ImageMagick allows remote attackers to cause a denial of... The xwd file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed xwd file. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-4) bullseye: resolved (fixed in 8:6.8.9.9-4) forky: resolved (fixed in 8:6.8.9.9-4) sid: resolved (fixed in 8:6.8.9.9-4) trixie: resolved (fixed in 8:6.8.
debian
CVE-2005-0760P4MEDIUMCVSS 5.0fixed in imagemagick 5:6.0.0-1 (bookworm)2005
CVE-2005-0760 [MEDIUM] CVE-2005-0760: imagemagick - The TIFF decoder in ImageMagick before 6.0 allows remote attackers to cause a de... The TIFF decoder in ImageMagick before 6.0 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file. Scope: local bookworm: resolved (fixed in 5:6.0.0-1) bullseye: resolved (fixed in 5:6.0.0-1) forky: resolved (fixed in 5:6.0.0-1) sid: resolved (fixed in 5:6.0.0-1) trixie: resolved (fixed in 5:6.0.0-1)
debian
CVE-2007-4985P4MEDIUMCVSS 4.3fixed in graphicsmagick 1.1.11-1 (bookworm)2007
CVE-2007-4985 [MEDIUM] CVE-2007-4985: graphicsmagick - ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial ... ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlobByte function calls; or (2) an infinite loop in the ReadXCFImage function, related to ReadBlobMSBLong function calls. Scope: local bookworm: resolved (fixed in 1
debian
CVE-2021-39212P4MEDIUMCVSS 4.4fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-39212 [MEDIUM] CVE-2021-39212: imagemagick - ImageMagick is free software delivered as a ready-to-run binary distribution or ... ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be read and written when specifically excluded by a `module` policy in `policy.xml`. ex. . The issue has been r
debian
CVE-2014-9915P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-1 (bookworm)2014
CVE-2014-9915 [MEDIUM] CVE-2014-9915: imagemagick - Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause ... Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile. Scope: local bookworm: resolved (fixed in 8:6.8.9.9-1) bullseye: resolved (fixed in 8:6.8.9.9-1) forky: resolved (fixed in 8:6.8.9.9-1) sid: resolved (fixed in 8:6.8.9.9-1) trixie: resolved (fixed in 8:6.8.9.9-1)
debian
CVE-2005-0759P4MEDIUMCVSS 5.0fixed in imagemagick 5:6.0.0-1 (bookworm)2005
CVE-2005-0759 [MEDIUM] CVE-2005-0759: imagemagick - ImageMagick before 6.0 allows remote attackers to cause a denial of service (app... ImageMagick before 6.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image with an invalid tag. Scope: local bookworm: resolved (fixed in 5:6.0.0-1) bullseye: resolved (fixed in 5:6.0.0-1) forky: resolved (fixed in 5:6.0.0-1) sid: resolved (fixed in 5:6.0.0-1) trixie: resolved (fixed in 5:6.0.0-1)
debian
CVE-2003-0455P4MEDIUMCVSS 4.6fixed in imagemagick 4:5.5.7-1 (bookworm)2003
CVE-2003-0455 [MEDIUM] CVE-2003-0455: imagemagick - The imagemagick libmagick library 5.5 and earlier creates temporary files insecu... The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files. Scope: local bookworm: resolved (fixed in 4:5.5.7-1) bullseye: resolved (fixed in 4:5.5.7-1) forky: resolved (fixed in 4:5.5.7-1) sid: resolved (fixed in 4:5.5.7-1) trixie: resolved (fixed in 4:5.5.7-1)
debian
CVE-2020-27768P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27768 [LOW] CVE-2020-27768: imagemagick - In ImageMagick, there is an outside the range of representable values of type 'u... In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h. This flaw affects ImageMagick versions prior to 7.0.9-0. Scope: local bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1) bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1) forky: resolved (fixed in 8:6.9.11.24+dfsg-1) sid: resolved (fixed in 8
debian
CVE-2020-27764P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27764 [LOW] CVE-2020-27764: imagemagick - In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() w... In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a crafted input file is processed by ImageMagick. Red Hat Product Security marked this as Low severity because although it could potentially lead to an impact to applicat
debian
CVE-2020-27774P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27774 [LOW] CVE-2020-27774: imagemagick - A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submi... A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavio
debian
CVE-2020-27772P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27772 [LOW] CVE-2020-27772: imagemagick - A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a craft... A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned int`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. Thi
debian
CVE-2020-27775P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27775 [LOW] CVE-2020-27775: imagemagick - A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits... A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned char. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavi
debian
CVE-2020-27758P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27758 [LOW] CVE-2020-27758: imagemagick - A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a craft... A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavio
debian
CVE-2020-27751P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27751 [LOW] CVE-2020-27751: imagemagick - A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who ... A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long` as well as a shift exponent that is too large for 64-bit type. This would most likely lead to an impact to application availabi
debian
CVE-2020-27761P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27761 [LOW] CVE-2020-27761: imagemagick - WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calcu... WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outside the range of representable type `unsigned long` undefined behavior when a crafted input file was processed by ImageMagick. The patch casts to `ssize_t` instead to avoid this issue. Red Hat Product Security marked the Severity as Low because al
debian
CVE-2020-25675P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-25675 [LOW] CVE-2020-25675: imagemagick - In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, ro... In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconstrained pixel offsets was causing undefined behavior in the form of integer overflow and out-of-range values as reported by UndefinedBehaviorSanitizer. Such issues could cause a negative impact to application availability or other problems relate
debian
CVE-2020-27776P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27776 [LOW] CVE-2020-27776: imagemagick - A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submi... A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned long. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined beha
debian
CVE-2005-0761P4MEDIUMCVSS 5.0fixed in imagemagick 5:6.0.2.5 (bookworm)2005
CVE-2005-0761 [MEDIUM] CVE-2005-0761: imagemagick - Unknown vulnerability in ImageMagick before 6.1.8 allows remote attackers to cau... Unknown vulnerability in ImageMagick before 6.1.8 allows remote attackers to cause a denial of service (application crash) via a crafted PSD file. Scope: local bookworm: resolved (fixed in 5:6.0.2.5) bullseye: resolved (fixed in 5:6.0.2.5) forky: resolved (fixed in 5:6.0.2.5) sid: resolved (fixed in 5:6.0.2.5) trixie: resolved (fixed in 5:6.0.2.5)
debian
Debian Imagemagick vulnerabilities | cvebase