Vulnerabilities > Imagemagick > High

DATE CVE VULNERABILITY TITLE RISK
2017-09-20 CVE-2017-14607 Out-of-bounds Read vulnerability in multiple products
In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c.
network
low complexity
imagemagick debian canonical CWE-125
8.1
2017-09-09 CVE-2017-14224 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick 7.0.68
A heap-based buffer overflow in WritePCXImage in coders/pcx.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service or code execution via a crafted file.
network
low complexity
imagemagick CWE-119
8.8
2017-09-04 CVE-2017-14137 Resource Exhaustion vulnerability in Imagemagick 7.0.65
ReadWEBPImage in coders/webp.c in ImageMagick 7.0.6-5 has an issue where memory allocation is excessive because it depends only on a length field in a header.
network
low complexity
imagemagick CWE-400
7.5
2017-08-23 CVE-2017-13146 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick
In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.c.
network
low complexity
imagemagick CWE-772
8.8
2017-08-23 CVE-2017-13143 Information Exposure vulnerability in Imagemagick
In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.
network
low complexity
imagemagick CWE-200
7.5
2017-08-21 CVE-2017-12983 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick 7.0.68
Heap-based buffer overflow in the ReadSFWImage function in coders/sfw.c in ImageMagick 7.0.6-8 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
network
low complexity
imagemagick CWE-119
8.8
2017-08-07 CVE-2017-12669 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.62
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteCALSImage in coders/cals.c.
network
low complexity
imagemagick CWE-772
8.8
2017-08-07 CVE-2017-12668 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.62
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePCXImage in coders/pcx.c.
network
low complexity
imagemagick CWE-772
8.8
2017-08-07 CVE-2017-12667 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.61
ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadMATImage in coders\mat.c.
network
low complexity
imagemagick CWE-772
8.8
2017-08-07 CVE-2017-12666 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.62
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteINLINEImage in coders/inline.c.
network
low complexity
imagemagick CWE-772
8.8