Debian Imagemagick vulnerabilities
674 known vulnerabilities affecting debian/imagemagick.
Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257
Vulnerabilities
Page 34 of 34
CVE-2025-68469P4LOWCVSS 2.0fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm)2025
CVE-2025-68469 [LOW] CVE-2025-68469: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u5)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u8)
forky: resolved (fixe
debian
CVE-2020-27560P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.57+dfsg-1 (bookworm)2020
CVE-2020-27560 [LOW] CVE-2020-27560: imagemagick - ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCo...
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.57+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.57+dfsg-1)
forky: resolved (fixed in 8:6.9.11.57+dfsg-1)
sid: resolved (fixed in 8:6.9.11.57+dfsg-1)
trixie: resolved (fixed in 8:6.9.11
debian
CVE-2020-25666P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-25666 [LOW] CVE-2020-25666: imagemagick - There are 4 places in HistogramCompare() in MagickCore/histogram.c where an inte...
There are 4 places in HistogramCompare() in MagickCore/histogram.c where an integer overflow is possible during simple math calculations. This occurs in the rgb values and `count` value for a color. The patch uses casts to `ssize_t` type for these calculations, instead of `int`. This flaw could impact application reliability in the event that ImageMagick processe
debian
CVE-2020-27771P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27771 [LOW] CVE-2020-27771: imagemagick - In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to G...
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts the return value of GetPixelIndex() to ssize_t type to avoid this bug. This undefined behavior could be triggered when ImageMagick processes a crafted pdf file. Red Hat
debian
CVE-2020-27759P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27759 [LOW] CVE-2020-27759: imagemagick - In IntensityCompare() of /MagickCore/quantize.c, a double value was being casted...
In IntensityCompare() of /MagickCore/quantize.c, a double value was being casted to int and returned, which in some cases caused a value outside the range of type `int` to be returned. The flaw could be triggered by a crafted input file under certain conditions when processed by ImageMagick. Red Hat Product Security marked this as Low severity because although it
debian
CVE-2020-27767P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27767 [LOW] CVE-2020-27767: imagemagick - A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits...
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to u
debian
CVE-2020-27754P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27754 [LOW] CVE-2020-27754: imagemagick - In IntensityCompare() of /magick/quantize.c, there are calls to PixelPacketInten...
In IntensityCompare() of /magick/quantize.c, there are calls to PixelPacketIntensity() which could return overflowed values to the caller when ImageMagick processes a crafted input file. To mitigate this, the patch introduces and uses the ConstrainPixelIntensity() function, which forces the pixel intensities to be within the proper bounds in the event of an overf
debian
CVE-2020-27757P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27757 [LOW] CVE-2020-27757: imagemagick - A floating point math calculation in ScaleAnyToQuantum() of /MagickCore/quantum-...
A floating point math calculation in ScaleAnyToQuantum() of /MagickCore/quantum-private.h could lead to undefined behavior in the form of a value outside the range of type unsigned long long. The flaw could be triggered by a crafted input file under certain conditions when it is processed by ImageMagick. Red Hat Product Security marked this as Low because althoug
debian
CVE-2020-27769P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27769 [LOW] CVE-2020-27769: imagemagick - In ImageMagick versions before 7.0.9-0, there are outside the range of represent...
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in 8:6.9.11.24+dfsg-1)
sid: resolved (fixed in 8:6.9.11.24+dfsg-1)
trixie: resolved (fixed in 8:6
debian
CVE-2020-27765P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27765 [LOW] CVE-2020-27765: imagemagick - A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits...
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects Ima
debian
CVE-2020-27773P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27773 [LOW] CVE-2020-27773: imagemagick - A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who sub...
A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` or division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems r
debian
CVE-2020-27763P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27763 [LOW] CVE-2020-27763: imagemagick - A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits ...
A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects Imag
debian
CVE-2020-27755P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27755 [LOW] CVE-2020-27755: imagemagick - in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can ca...
in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size. The patch resets the depth to a proper size before throwing an exception. The memory leak can be triggered by a crafted input file that is pro
debian
CVE-2021-3574P4LOWCVSS 3.3fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-3574 [LOW] CVE-2021-3574: imagemagick - A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted fil...
A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u2)
forky: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
sid: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
trixie: resolve
debian
← Previous34 / 34