Vulnerabilities > Imagemagick > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-06-02 CVE-2017-9405 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.55
In ImageMagick 7.0.5-5, the ReadICONImage function in icon.c:452 allows attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick CWE-772
6.5
2017-05-29 CVE-2017-9262 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.56
In ImageMagick 7.0.5-6 Q16, the ReadJNGImage function in coders/png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick CWE-772
6.5
2017-05-29 CVE-2017-9261 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.56
In ImageMagick 7.0.5-6 Q16, the ReadMNGImage function in coders/png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick CWE-772
6.5
2017-05-22 CVE-2017-9144 Improper Input Validation vulnerability in multiple products
In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c.
network
low complexity
imagemagick debian CWE-20
6.5
2017-05-22 CVE-2017-9143 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.5-5, the ReadARTImage function in coders/art.c allows attackers to cause a denial of service (memory leak) via a crafted .art file.
network
low complexity
imagemagick debian CWE-772
6.5
2017-05-22 CVE-2017-9142 Reachable Assertion vulnerability in multiple products
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing checks in the ReadOneJNGImage function in coders/png.c.
network
low complexity
imagemagick debian CWE-617
6.5
2017-05-22 CVE-2017-9141 Reachable Assertion vulnerability in multiple products
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c because of missing checks in the ReadDDSImage function in coders/dds.c.
network
low complexity
imagemagick debian CWE-617
6.5
2017-05-08 CVE-2017-8830 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.56
In ImageMagick 7.0.5-6, the ReadBMPImage function in bmp.c:1379 allows attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick CWE-772
6.5
2017-05-04 CVE-2017-8765 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.55
The function named ReadICONImage in coders\icon.c in ImageMagick 7.0.5-5 has a memory leak vulnerability which can cause memory exhaustion via a crafted ICON file.
network
low complexity
imagemagick CWE-772
6.5
2017-04-30 CVE-2017-8357 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.5-5, the ReadEPTImage function in ept.c allows attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick debian CWE-772
6.5