Vulnerabilities > Imagemagick > Imagemagick > 6.0.6.2

DATE CVE VULNERABILITY TITLE RISK
2007-09-24 CVE-2007-4988 Incorrect Conversion between Numeric Types vulnerability in multiple products
Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.
local
low complexity
imagemagick canonical CWE-681
7.8
2007-09-24 CVE-2007-4987 Numeric Errors vulnerability in Imagemagick
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.
network
imagemagick CWE-189
critical
9.3
2007-09-24 CVE-2007-4986 Numeric Errors vulnerability in Imagemagick
Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.
6.8
2007-09-24 CVE-2007-4985 Resource Management Errors vulnerability in Imagemagick
ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlobByte function calls; or (2) an infinite loop in the ReadXCFImage function, related to ReadBlobMSBLong function calls.
4.3
2006-08-25 CVE-2006-3744 Numeric Errors vulnerability in Imagemagick
Multiple integer overflows in ImageMagick before 6.2.9 allows user-assisted attackers to execute arbitrary code via crafted Sun Rasterfile (bitmap) images that trigger heap-based buffer overflows.
network
high complexity
imagemagick CWE-189
5.1
2006-05-18 CVE-2006-2440 Remote Security vulnerability in Imagemagick 6.0.6.2/6.2.4
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
network
low complexity
imagemagick
7.5
2005-11-16 CVE-2005-3582 Packages Insecure RUNPATH vulnerability in Gentoo Linux
ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
local
low complexity
imagemagick
7.2