Vulnerabilities > Imagemagick

DATE CVE VULNERABILITY TITLE RISK
2006-10-23 CVE-2006-5456 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.
network
high complexity
graphicsmagick imagemagick CWE-119
5.1
2006-08-25 CVE-2006-3744 Numeric Errors vulnerability in Imagemagick
Multiple integer overflows in ImageMagick before 6.2.9 allows user-assisted attackers to execute arbitrary code via crafted Sun Rasterfile (bitmap) images that trigger heap-based buffer overflows.
network
high complexity
imagemagick CWE-189
5.1
2006-08-25 CVE-2006-3743 Buffer Overflow vulnerability in ImageMagick XCF Image File Remote
Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.
network
high complexity
imagemagick
5.1
2006-08-15 CVE-2006-4144 Remote Heap Buffer Overflow vulnerability in ImageMagick SGI Image File
Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow.
network
high complexity
imagemagick
2.6
2006-05-18 CVE-2006-2440 Remote Security vulnerability in Imagemagick 6.0.6.2/6.2.4
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
network
low complexity
imagemagick
7.5
2006-01-04 CVE-2006-0082 USE of Externally-Controlled Format String vulnerability in Imagemagick 6.2.3
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
network
high complexity
imagemagick CWE-134
5.1
2005-12-31 CVE-2005-4601 Remote Command Execution vulnerability in Imagemagick 6.2.4.5
The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.
network
low complexity
imagemagick
7.5
2005-11-16 CVE-2005-3582 Packages Insecure RUNPATH vulnerability in Gentoo Linux
ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
local
low complexity
imagemagick
7.2
2005-05-24 CVE-2005-1739 Denial Of Service vulnerability in ImageMagick And GraphicsMagick XWD Decoder
The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.
network
low complexity
graphicsmagick imagemagick
5.0
2005-05-02 CVE-2005-0762 Unspecified vulnerability in Imagemagick
Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows remote attackers to execute arbitrary code via a crafted SGI image file.
network
low complexity
imagemagick
7.5