Debian Imagemagick vulnerabilities
674 known vulnerabilities affecting debian/imagemagick.
Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257
Vulnerabilities
Page 4 of 34
CVE-2025-62171P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm)2025
CVE-2025-62171 [HIGH] CVE-2025-62171: imagemagick - ImageMagick is an open source software suite for displaying, converting, and edi...
ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. O
debian
CVE-2018-12599P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.10.2+dfsg-2 (bookworm)2018
CVE-2018-12599 [HIGH] CVE-2018-12599: imagemagick - In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow...
In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.10.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.10.2+dfsg-2)
forky: resolved (fixed in 8:6.9.10.2+dfsg-2)
sid: resolved (fixed in 8:6.9.10.2+dfsg-2)
trixie: resolved (fixed
debian
CVE-2018-12600P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.10.2+dfsg-2 (bookworm)2018
CVE-2018-12600 [HIGH] CVE-2018-12600: imagemagick - In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow...
In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.10.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.10.2+dfsg-2)
forky: resolved (fixed in 8:6.9.10.2+dfsg-2)
sid: resolved (fixed in 8:6.9.10.2+dfsg-2)
trixie: resolved (fixed
debian
CVE-2025-66628P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm)2025
CVE-2025-66628 [HIGH] CVE-2025-66628: imagemagick - ImageMagick is a software suite to create, edit, compose, or convert bitmap imag...
ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height withou
debian
CVE-2019-13300P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-13300 [HIGH] CVE-2019-13300: imagemagick - ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statisti...
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in 8:6.9.11.24+dfsg-1)
sid: resolved (fixed in 8:6.9.11.24+dfsg-1)
trixie: resolved (fixed in 8:
debian
CVE-2026-25967P3LOWCVSS 7.4fixed in imagemagick 8:7.1.2.15+dfsg1-1 (forky)2026
CVE-2026-25967 [HIGH] CVE-2026-25967: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a stack-based buffer overflow exists in the ImageMagick FTXT image reader. A crafted FTXT file can cause out-of-bounds writes on the stack, leading to a crash. Version 7.1.2-15 contains a patch.
Scope: local
bookworm: resolved
bullseye: resol
debian
CVE-2014-9831P3HIGHCVSS 8.8fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9831 [HIGH] CVE-2014-9831: imagemagick - coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact v...
coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2017-15277P3MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-14 (bookworm)2017
CVE-2017-15277 [MEDIUM] CVE-2017-15277: graphicsmagick - ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 le...
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.
Scope: lo
debian
CVE-2016-5687P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-5687 [CRITICAL] CVE-2016-5687: imagemagick - The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7...
The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
debian
CVE-2016-4564P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-4564 [CRITICAL] CVE-2016-4564: imagemagick - The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7....
The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to locate the next token, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
Scope: local
bookworm: resolved
debian
CVE-2017-17499P3CRITICALCVSS 9.8fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-17499 [CRITICAL] CVE-2017-17499: imagemagick - ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magi...
ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid: resolved (fixed in 8:6.9.9.34+dfsg-3)
trixie: resolved (fixed in 8:6.9.9.34+df
debian
CVE-2025-68618P3MEDIUMCVSS 5.3fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm)2025
CVE-2025-68618 [MEDIUM] CVE-2025-68618: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u5)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u8)
forky:
debian
CVE-2025-69204P3MEDIUMCVSS 5.3fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm)2025
CVE-2025-69204 [MEDIUM] CVE-2025-69204: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue.
Scope: local
bookworm: resolve
debian
CVE-2025-53015P3LOWCVSS 7.5fixed in imagemagick 8:7.1.1.47+dfsg1-2 (forky)2025
CVE-2025-53015 [HIGH] CVE-2025-53015: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 8:7.1.1.47+dfsg1-2)
sid: resolved (fixed in 8:7.
debian
CVE-2026-30929P3LOWCVSS 7.7fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-30929 [HIGH] CVE-2026-30929: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MagnifyImage uses a fixed-size stack buffer. When using a specific image it is possible to overflow this buffer and corrupt the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Scope: local
bookworm: resolved
bulls
debian
CVE-2026-25985P3HIGHCVSS 7.5fixed in imagemagick 8:7.1.2.15+dfsg1-1 (forky)2026
CVE-2026-25985 [HIGH] CVE-2026-25985: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Scope: local
bookworm: open
bul
debian
CVE-2019-13308P3LOWCVSS 8.8fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-13308 [HIGH] CVE-2019-13308: imagemagick - ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier....
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in 8:6.9.11.24+dfsg-1)
sid: resolved (fixed in 8:6.9.11.24+dfsg-1)
trixie: resolved (fixed in 8:6.9.11.24+dfsg-1)
debian
CVE-2009-1882P3MEDIUMCVSS 9.3fixed in graphicsmagick 1.3.5-5.1 (bookworm)2009
CVE-2009-1882 [CRITICAL] CVE-2009-1882: graphicsmagick - Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6...
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: r
debian
CVE-2014-9830P3HIGHCVSS 8.8fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9830 [HIGH] CVE-2014-9830: imagemagick - coders/sun.c in ImageMagick allows remote attackers to have unspecified impact v...
coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2016-8707P3HIGHCVSS 7.8fixed in imagemagick 8:6.9.7.0+dfsg-2 (bookworm)2016
CVE-2016-8707 [HIGH] CVE-2016-8707: imagemagick - An exploitable out of bounds write exists in the handling of compressed TIFF ima...
An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.
debian