Where
AND
-Infinity
0

Vendor Risk Score

See how imagemagick compares to other vendors in security performance

View Risk Score →
Severity
2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Rejected reason: This CVE ID has been rejected as a duplicate.

First published (updated )
Severity
1.8
AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.

First published (updated )
Severity
2.3
EPSS
0.26%
Null Pointer Dereference
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NULL pointer is dereferenced, which can lead to a denial of service (application crash) when processing a specially crafted or sufficiently large PNM image.

1 / 2
Source: MITRE
First published (updated )
Severity
2.1
EPSS
0.11%
Use After Free
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.

1 / 2
Source: MITRE
First published (updated )
Severity
2
AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.

First published (updated )
Severity
1
Race Condition
AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.

First published (updated )
Severity
2
AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes allocated memory not to be released, which can lead to increased memory consumption.

First published (updated )
Severity
2.1
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.

First published (updated )
Severity
2.1
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.

First published (updated )
Severity
2.1
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.

1 / 2
Source: NVD
First published (updated )
Severity
2.1
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

1 / 2
Source: NVD
First published (updated )
Severity
2.1
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released.

1 / 2
Source: NVD
First published (updated )
Severity
2.1
AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

First published (updated )
Severity
2.1
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.

1 / 2
Source: MITRE
First published (updated )
Severity
1
AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.

First published (updated )
Severity
2.1
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

1 / 2
Source: MITRE
First published (updated )
Severity
2.1
AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.

First published (updated )
Severity
1.8
AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

First published (updated )
Severity
3.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.

First published (updated )
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.

First published (updated )
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.

1 / 2
First published (updated )
Severity
1

In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.

Upstream issue:

https://github.com/ImageMagick/ImageMagick/issues/1118

First published (updated )
Severity
1

In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBlob assertion failure and application exit) via a crafted file.

Upstream issue:

https://github.com/ImageMagick/ImageMagick/issues/1119

Upstream patch:

https://github.com/ImageMagick/ImageMagick6/commit/1007b98f8795ad4bea6bc5f68a32d83e982fdae4

First published (updated )
Severity
1
Null Pointer Dereference

A flaw was found in ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.

References: https://github.com/ImageMagick/ImageMagick/issues/1224

First published (updated )
Severity
1

A flaw was found in ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c.

References: https://github.com/ImageMagick/ImageMagick/issues/1195

Upstream Patch: https://github.com/ImageMagick/ImageMagick/commit/4ab4849d667e26df0e63ece9d63ae23bc7ab0fa1 https://github.com/ImageMagick/ImageMagick6/commit/6ce6d25b47caf9b6b2979a510b6202ce0f3dd2d4

First published (updated )
Severity
1

A flaw was found in ImageMagick 7.0.7-20 Q16 x8664, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.

References: https://github.com/ImageMagick/ImageMagick/issues/931

Patch: https://github.com/ImageMagick/ImageMagick/commit/4da2cd650532ffd18fa11578fc2ec7c2467727bb

First published (updated )
Severity
1

A flaw was found in ImageMagick 7.0.7-16 Q16 x8664 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted MIFF image file.

References: https://github.com/ImageMagick/ImageMagick/issues/911

Patch: https://github.com/ImageMagick/ImageMagick/commit/7523250e2664028aa1d8f02d2d7ae49c769a851e

First published (updated )
Severity
1

In ImageMagick 7.0.7-16 Q16 x8664 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.

References: https://github.com/ImageMagick/ImageMagick/issues/910

Patch: https://github.com/ImageMagick/ImageMagick/commit/d95991f24d27dbc335dfa7c0523c886ab9329e9e

First published (updated )
Severity
1

A flaw was found in ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.

References: https://github.com/ImageMagick/ImageMagick/issues/1053

First published (updated )
Severity
1

A flaw was found in ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.

References: https://github.com/ImageMagick/ImageMagick/issues/1054

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203