Vulnerabilities > Imagemagick

DATE CVE VULNERABILITY TITLE RISK
2020-12-08 CVE-2020-27756 Unspecified vulnerability in Imagemagick
In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculations can lead to divide-by-zero conditions which also lead to undefined behavior.
local
low complexity
imagemagick
5.5
2020-12-08 CVE-2020-27755 Unspecified vulnerability in Imagemagick
in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size.
local
low complexity
imagemagick
3.3
2020-12-08 CVE-2020-27754 In IntensityCompare() of /magick/quantize.c, there are calls to PixelPacketIntensity() which could return overflowed values to the caller when ImageMagick processes a crafted input file.
local
low complexity
imagemagick debian
3.3
2020-12-08 CVE-2020-27753 Unspecified vulnerability in Imagemagick
There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be triggered by a specially crafted input file.
local
low complexity
imagemagick
5.5
2020-12-08 CVE-2020-27752 Unspecified vulnerability in Imagemagick
A flaw was found in ImageMagick in MagickCore/quantum-private.h.
network
low complexity
imagemagick
7.1
2020-12-08 CVE-2020-27751 Integer Overflow or Wraparound vulnerability in multiple products
A flaw was found in ImageMagick in MagickCore/quantum-export.c.
local
low complexity
imagemagick debian CWE-190
3.3
2020-12-08 CVE-2020-27750 A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h.
local
low complexity
imagemagick debian
5.5
2020-12-08 CVE-2020-25676 In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in /MagickCore/pixel.c, there were multiple unconstrained pixel offset calculations which were being used with the floor() function.
local
low complexity
imagemagick debian
5.5
2020-12-08 CVE-2020-25675 In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconstrained pixel offsets was causing undefined behavior in the form of integer overflow and out-of-range values as reported by UndefinedBehaviorSanitizer.
local
low complexity
imagemagick debian
3.3
2020-12-08 CVE-2020-25674 WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buffer-overflow.
local
low complexity
imagemagick debian
5.5