Vulnerabilities > Imagemagick

DATE CVE VULNERABILITY TITLE RISK
2017-08-04 CVE-2017-12428 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.61
In ImageMagick 7.0.6-1, a memory leak vulnerability was found in the function ReadWMFImage in coders/wmf.c, which allows attackers to cause a denial of service in CloneDrawInfo in draw.c.
network
low complexity
imagemagick CWE-772
7.5
2017-08-04 CVE-2017-12427 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick
The ProcessMSLScript function in coders/msl.c in ImageMagick before 6.9.9-5 and 7.x before 7.0.6-5 allows remote attackers to cause a denial of service (memory leak) via a crafted file, related to the WriteMSLImage function.
network
low complexity
imagemagick CWE-772
6.5
2017-08-04 CVE-2017-12418 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.65
ImageMagick 7.0.6-5 has memory leaks in the parse8BIMW and format8BIM functions in coders/meta.c, related to the WriteImage function in MagickCore/constitute.c.
network
low complexity
imagemagick CWE-772
7.5
2017-08-02 CVE-2017-12140 Incorrect Conversion between Numeric Types vulnerability in Imagemagick 7.0.61
The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive memory consumption via a crafted DCM file.
network
low complexity
imagemagick CWE-681
6.5
2017-07-30 CVE-2017-11755 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.64
The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an AcquireSemaphoreInfo call.
network
low complexity
imagemagick CWE-772
6.5
2017-07-30 CVE-2017-11754 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.64
The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an OpenPixelCache call.
network
low complexity
imagemagick CWE-772
6.5
2017-07-30 CVE-2017-11753 Out-of-bounds Read vulnerability in Imagemagick 7.0.64
The GetImageDepth function in MagickCore/attribute.c in ImageMagick 7.0.6-4 might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted Flexible Image Transport System (FITS) file.
network
low complexity
imagemagick CWE-125
6.5
2017-07-30 CVE-2017-11752 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.64
The ReadMAGICKImage function in coders/magick.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick CWE-772
6.5
2017-07-30 CVE-2017-11751 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.64
The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick CWE-772
6.5
2017-07-30 CVE-2017-11750 NULL Pointer Dereference vulnerability in Imagemagick 6.9.94/7.0.64
The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
network
low complexity
imagemagick CWE-476
6.5