cbcvebase.

Debian Imagemagick vulnerabilities

674 known vulnerabilities affecting debian/imagemagick.

Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257

Vulnerabilities

Page 5 of 34
CVE-2026-30931P3LOWCVSS 6.8fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-30931 [MEDIUM] CVE-2026-30931: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, a heap-based buffer overflow in the UHDR encoder can happen due to truncation of a value and it would allow an out of bounds write. This vulnerability is fixed in 7.1.2-16. Scope: local bookworm: resolved bullseye: resolved forky: resolved
debian
CVE-2017-18211P3LOWCVSS 9.8fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-18211 [CRITICAL] CVE-2017-18211: imagemagick - In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the ... In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-lookup result is not checked, related to CacheOpenCLKernel. Scope: local bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3) bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3) forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
debian
CVE-2005-4601P3HIGHCVSS 7.5fixed in graphicsmagick 1.1.7-1 (bookworm)2005
CVE-2005-4601 [HIGH] CVE-2005-4601: graphicsmagick - The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute ... The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command. Scope: local bookworm: resolved (fixed in 1.1.7-1) bullseye: resolved (fixed in 1.1.7-1) forky: resolved (fixed in 1.1.7-1) sid: resolved (fixed in 1.1.7-1) trixie: resolved (fixed in
debian
CVE-2017-9098P3HIGHCVSS 7.5fixed in graphicsmagick 1.3.24-1 (bookworm)2017
CVE-2017-9098 [HIGH] CVE-2017-9098: graphicsmagick - ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized me... ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initia
debian
CVE-2026-26283P3MEDIUMCVSS 6.2fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-26283 [MEDIUM] CVE-2026-26283: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a `continue` statement in the JPEG extent binary search loop in the jpeg encoder causes an infinite loop when writing persistently fails. An attacker can trigger a 100% CPU consumption and process hang (Denial of Service) wit
debian
CVE-2021-3610P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm)2021
CVE-2021-3610 [HIGH] CVE-2021-3610: imagemagick - A heap-based buffer overflow vulnerability was found in ImageMagick in versions ... A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault. Scope: local bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u1) bullseye: resolved (fixed in 8:6.9.11.60+
debian
CVE-2021-20312P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-20312 [HIGH] CVE-2021-20312: imagemagick - A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in... A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved
debian
CVE-2026-25966P3LOWCVSS 5.9fixed in imagemagick 8:7.1.2.15+dfsg1-1 (forky)2026
CVE-2026-25966 [MEDIUM] CVE-2026-25966: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule intended to prevent reading/writing from standard streams. However, ImageMagick also supports fd: pseudo-filenames (e.g., fd:0, fd:1). Prior to versions 7.1.2-15 and 6.9.13-40, this path form is not blocked by the
debian
CVE-2021-20313P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-20313 [HIGH] CVE-2021-20313: imagemagick - A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher le... A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality. Scope: local bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5) bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u4) forky: resolved (fixed
debian
CVE-2026-30883P3MEDIUMCVSS 5.7fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-30883 [MEDIUM] CVE-2026-30883: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an extremely large image profile could result in a heap overflow when encoding a PNG image. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 8:7.1.2.1
debian
CVE-2026-25970P3MEDIUMCVSS 5.3fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25970 [MEDIUM] CVE-2026-25970: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs dur
debian
CVE-2026-25989P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25989 [HIGH] CVE-2026-25989: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (`>` instead of `>=`) that allows bypass the guard and reach an undefined `(size_t)` cast. Versions 7.1.2-15 and 6.9.13-40 contain a patch. Scope: l
debian
CVE-2025-55154P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm)2025
CVE-2025-55154 [HIGH] CVE-2025-55154: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1. Scope: local bookworm: resolved (fixe
debian
CVE-2025-55212P3LOWCVSS 3.7fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm)2025
CVE-2025-55212 [LOW] CVE-2025-55212: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (":") to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these zero dimensions, triggering a crash (SIGFPE/abort), resulting in
debian
CVE-2021-20309P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)2021
CVE-2021-20309 [HIGH] CVE-2021-20309: imagemagick - A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, whe... A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an application using ImageMagick. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 8
debian
CVE-2026-25988P3MEDIUMCVSS 5.3fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25988 [MEDIUM] CVE-2026-25988: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image is stored in the wrong slot and never freed on error, causing leaks. Versions 7.1.2-15 and 6.9.13-40 contain a patch. Scope: local bookworm: resolved (fixed in 8:6.
debian
CVE-2026-25799P3MEDIUMCVSS 5.3fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u7 (bookworm)2026
CVE-2026-25799 [MEDIUM] CVE-2026-25799: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d... ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-4
debian
CVE-2017-10928P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.7.4+dfsg-12 (bookworm)2017
CVE-2017-10928 [HIGH] CVE-2017-10928: imagemagick - In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken functi... In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c. Scope: local bookworm: resolved (fixed in 8:6
debian
CVE-2019-13135P3HIGHCVSS 8.8fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2019
CVE-2019-13135 [HIGH] CVE-2019-13135: imagemagick - ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in ... ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c. Scope: local bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1) bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1) forky: resolved (fixed in 8:6.9.11.24+dfsg-1) sid: resolved (fixed in 8:6.9.11.24+dfsg-1) trixie: resolved (fixed in 8:6.9.11.24+d
debian
CVE-2016-5842P3HIGHCVSS 7.5fixed in imagemagick 8:6.9.6.2+dfsg-2 (bookworm)2016
CVE-2016-5842 [HIGH] CVE-2016-5842: imagemagick - MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to o... MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read. Scope: local bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2) bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2) forky: resolved (fixed in 8:6.9.6.2+dfsg-2) sid: resolved (fixed in
debian
Debian Imagemagick vulnerabilities | cvebase