Vulnerabilities > Imagemagick > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-12-13 CVE-2016-5687 Out-of-bounds Read vulnerability in multiple products
The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-bounds read.
network
low complexity
imagemagick oracle CWE-125
critical
9.8
2016-06-10 CVE-2016-5118 The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
network
low complexity
graphicsmagick suse oracle opensuse canonical debian imagemagick
critical
9.8
2009-06-02 CVE-2009-1882 Numeric Errors vulnerability in Imagemagick 6.5.28
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow.
network
imagemagick CWE-189
critical
9.3
2007-09-24 CVE-2007-4987 Numeric Errors vulnerability in Imagemagick
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.
network
imagemagick CWE-189
critical
9.3
2007-02-12 CVE-2007-0770 Denial-Of-Service vulnerability in ImageMagick
Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.
network
graphicsmagick imagemagick
critical
9.3
2006-11-22 CVE-2006-5868 Remote Heap Buffer Overflow vulnerability in ImageMagick SGI Image File
Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image.
network
imagemagick debian canonical
critical
9.3
2005-02-09 CVE-2004-0981 Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
network
low complexity
imagemagick debian gentoo suse
critical
10.0