Vulnerabilities > Imagemagick > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-03-24 CVE-2016-10144 Improper Access Control vulnerability in Imagemagick
coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
network
low complexity
imagemagick CWE-284
critical
9.8
2017-03-20 CVE-2014-9847 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
network
low complexity
opensuse-project opensuse canonical imagemagick CWE-119
critical
9.8
2017-03-20 CVE-2014-9846 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
network
low complexity
opensuse-project suse opensuse canonical imagemagick CWE-119
critical
9.8
2017-03-20 CVE-2014-9843 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
network
low complexity
opensuse-project opensuse canonical imagemagick CWE-119
critical
9.8
2017-03-20 CVE-2014-9841 7PK - Errors vulnerability in multiple products
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
network
low complexity
opensuse-project opensuse canonical imagemagick CWE-388
critical
9.8
2017-03-17 CVE-2014-9852 Improper Control of Dynamically-Managed Code Resources vulnerability in multiple products
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.
network
low complexity
imagemagick suse opensuse CWE-913
critical
9.8
2017-03-15 CVE-2016-5239 Improper Access Control vulnerability in Imagemagick
The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
network
low complexity
imagemagick CWE-284
critical
9.8
2016-12-13 CVE-2016-6520 Out-of-bounds Read vulnerability in Imagemagick
Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.
network
low complexity
imagemagick CWE-125
critical
9.1
2016-12-13 CVE-2016-5841 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.
network
low complexity
imagemagick oracle CWE-190
critical
9.8
2016-12-13 CVE-2016-5691 Improper Input Validation vulnerability in multiple products
The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixel.blue.
network
low complexity
oracle imagemagick CWE-20
critical
9.8