Vulnerabilities > Imagemagick > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-08-07 CVE-2017-12671 Use After Free vulnerability in Imagemagick 7.0.63
In ImageMagick 7.0.6-3, a missing NULL assignment was found in coders/png.c, leading to an invalid free in the function RelinquishMagickMemory in MagickCore/memory.c, which allows attackers to cause a denial of service.
network
low complexity
imagemagick CWE-416
6.5
2017-08-07 CVE-2017-12670 Reachable Assertion vulnerability in Imagemagick 7.0.63
In ImageMagick 7.0.6-3, missing validation was found in coders/mat.c, leading to an assertion failure in the function DestroyImage in MagickCore/image.c, which allows attackers to cause a denial of service.
network
low complexity
imagemagick CWE-617
6.5
2017-08-07 CVE-2017-12654 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.63
The ReadPICTImage function in coders/pict.c in ImageMagick 7.0.6-3 allows attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick CWE-772
6.5
2017-08-07 CVE-2017-12643 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
ImageMagick 7.0.6-1 has a memory exhaustion vulnerability in ReadOneJNGImage in coders\png.c.
network
low complexity
imagemagick debian CWE-770
6.5
2017-08-05 CVE-2017-12566 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.62
In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadMVGImage in coders/mvg.c, which allows attackers to cause a denial of service, related to the function ReadSVGImage in svg.c.
network
low complexity
imagemagick CWE-772
6.5
2017-08-05 CVE-2017-12565 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.62
In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadOneJNGImage in coders/png.c, which allows attackers to cause a denial of service.
network
low complexity
imagemagick CWE-772
6.5
2017-08-05 CVE-2017-12564 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.62
In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service.
network
low complexity
imagemagick CWE-772
6.5
2017-08-05 CVE-2017-12563 Allocation of Resources Without Limits or Throttling vulnerability in Imagemagick 7.0.62
In ImageMagick 7.0.6-2, a memory exhaustion vulnerability was found in the function ReadPSDImage in coders/psd.c, which allows attackers to cause a denial of service.
network
low complexity
imagemagick CWE-770
6.5
2017-08-04 CVE-2017-12434 Reachable Assertion vulnerability in Imagemagick 7.0.61
In ImageMagick 7.0.6-1, a missing NULL check vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service (assertion failure) in DestroyImageInfo in image.c.
network
low complexity
imagemagick CWE-617
6.5
2017-08-04 CVE-2017-12433 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.61
In ImageMagick 7.0.6-1, a memory leak vulnerability was found in the function ReadPESImage in coders/pes.c, which allows attackers to cause a denial of service, related to ResizeMagickMemory in memory.c.
network
low complexity
imagemagick CWE-772
6.5