Vulnerabilities > Imagemagick

DATE CVE VULNERABILITY TITLE RISK
2017-09-07 CVE-2017-14172 Excessive Iteration vulnerability in multiple products
In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause huge CPU consumption.
network
low complexity
imagemagick debian canonical CWE-834
6.5
2017-09-04 CVE-2017-14139 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.62
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMSLImage in coders/msl.c.
network
low complexity
imagemagick CWE-772
6.5
2017-09-04 CVE-2017-14138 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.65
ImageMagick 7.0.6-5 has a memory leak vulnerability in ReadWEBPImage in coders/webp.c because memory is not freed in certain error cases, as demonstrated by VP8 errors.
network
low complexity
imagemagick CWE-772
critical
9.8
2017-09-04 CVE-2017-14137 Resource Exhaustion vulnerability in Imagemagick 7.0.65
ReadWEBPImage in coders/webp.c in ImageMagick 7.0.6-5 has an issue where memory allocation is excessive because it depends only on a length field in a header.
network
low complexity
imagemagick CWE-400
7.5
2017-09-01 CVE-2017-12693 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
The ReadBMPImage function in coders/bmp.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted BMP file.
network
low complexity
imagemagick canonical CWE-770
6.5
2017-09-01 CVE-2017-12692 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted VIFF file.
network
low complexity
imagemagick canonical CWE-770
6.5
2017-09-01 CVE-2017-12691 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
The ReadOneLayer function in coders/xcf.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
network
low complexity
imagemagick canonical CWE-770
6.5
2017-08-31 CVE-2017-14060 NULL Pointer Dereference vulnerability in multiple products
In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in the ReadCUTImage function in coders/cut.c that could allow an attacker to cause a Denial of Service (in the QueueAuthenticPixelCacheNexus function within the MagickCore/cache.c file) by submitting a malformed image file.
network
low complexity
imagemagick canonical CWE-476
6.5
2017-08-30 CVE-2017-13769 Out-of-bounds Read vulnerability in multiple products
The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an attacker to cause a denial of service (buffer over-read) by sending a crafted JPEG file.
network
low complexity
imagemagick canonical debian CWE-125
6.5
2017-08-30 CVE-2017-13768 NULL Pointer Dereference vulnerability in multiple products
Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker to perform denial of service by sending a crafted image file.
network
low complexity
imagemagick debian canonical CWE-476
6.5