Vulnerabilities > Imagemagick > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-21 CVE-2017-11505 Excessive Iteration vulnerability in Imagemagick
The ReadOneJNGImage function in coders/png.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a malformed JNG file.
7.1
2017-07-20 CVE-2017-11478 Infinite Loop vulnerability in Imagemagick
The ReadOneDJVUImage function in coders/djvu.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed DJVU image.
7.1
2017-07-19 CVE-2017-11446 Infinite Loop vulnerability in Imagemagick 7.0.61
The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU exhaustion via a crafted PES file.
7.1
2017-07-12 CVE-2017-11188 Excessive Iteration vulnerability in Imagemagick 7.0.60
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted DPX file, related to lack of an EOF check.
network
low complexity
imagemagick CWE-834
7.8
2017-07-10 CVE-2017-11166 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.56
The ReadXWDImage function in coders\xwd.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted length (number of color-map entries) field in the header of an XWD file.
7.1
2017-07-10 CVE-2017-11141 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.56
The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call.
7.1
2017-05-04 CVE-2017-8765 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.55
The function named ReadICONImage in coders\icon.c in ImageMagick 7.0.5-5 has a memory leak vulnerability which can cause memory exhaustion via a crafted ICON file.
7.1
2017-04-20 CVE-2015-8959 Resource Management Errors vulnerability in Imagemagick
coders/dds.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (CPU consumption) via a crafted DDS file.
7.1
2017-03-30 CVE-2014-9826 7PK - Errors vulnerability in Imagemagick
ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files.
network
low complexity
imagemagick CWE-388
7.5
2017-03-24 CVE-2017-5511 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer overflow.
network
low complexity
imagemagick CWE-119
7.5