Vulnerabilities > Imagemagick > Imagemagick > 5.4

DATE CVE VULNERABILITY TITLE RISK
2017-08-23 CVE-2017-13141 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick
In ImageMagick before 6.9.9-4 and 7.x before 7.0.6-4, a crafted file could trigger a memory leak in ReadOnePNGImage in coders/png.c.
4.3
2017-08-23 CVE-2017-13140 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick
In ImageMagick before 6.9.9-1 and 7.x before 7.0.6-2, the ReadOnePNGImage function in coders/png.c allows remote attackers to cause a denial of service (application hang in LockSemaphoreInfo) via a PNG file with a width equal to MAGICK_WIDTH_LIMIT.
4.3
2017-08-23 CVE-2017-13139 Out-of-bounds Read vulnerability in Imagemagick
In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.
network
low complexity
imagemagick CWE-125
7.5
2017-08-07 CVE-2014-9831 Improper Access Control vulnerability in Imagemagick
coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file.
network
low complexity
imagemagick CWE-284
8.8
2017-08-07 CVE-2014-9830 Improper Access Control vulnerability in Imagemagick
coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file.
network
low complexity
imagemagick CWE-284
8.8
2017-08-07 CVE-2014-9828 Improper Access Control vulnerability in Imagemagick
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file.
network
low complexity
imagemagick CWE-284
8.8
2017-08-07 CVE-2014-9827 Improper Access Control vulnerability in Imagemagick
coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file.
network
low complexity
imagemagick CWE-284
8.8
2017-08-04 CVE-2017-12427 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick
The ProcessMSLScript function in coders/msl.c in ImageMagick before 6.9.9-5 and 7.x before 7.0.6-5 allows remote attackers to cause a denial of service (memory leak) via a crafted file, related to the WriteMSLImage function.
4.3
2017-07-25 CVE-2016-7539 Resource Management Errors vulnerability in Imagemagick
Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
network
low complexity
imagemagick CWE-399
7.8
2017-07-23 CVE-2017-11530 Resource Exhaustion vulnerability in Imagemagick
The ReadEPTImage function in coders/ept.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
7.1