Vulnerabilities > Imagemagick > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-23 CVE-2016-10052 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick
Buffer overflow in the WriteProfile function in coders/jpeg.c in ImageMagick before 6.9.5-6 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
6.8
2017-03-23 CVE-2016-10051 Use After Free vulnerability in multiple products
Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
6.8
2017-03-23 CVE-2016-10050 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.
6.8
2017-03-23 CVE-2016-10049 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick before 6.9.4-4 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.
6.8
2017-03-23 CVE-2016-10048 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.
network
low complexity
imagemagick opensuse-project CWE-22
5.0
2017-03-23 CVE-2016-10046 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick
Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
4.3
2017-03-23 CVE-2014-9915 Numeric Errors vulnerability in Imagemagick
Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.
4.3
2017-03-22 CVE-2014-9840 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick 6.8.99
ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted palm file.
4.3
2017-03-22 CVE-2014-9839 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick 6.8.99
magick/colormap-private.h in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds access).
network
low complexity
imagemagick CWE-119
5.0
2017-03-22 CVE-2014-9838 Unspecified vulnerability in Imagemagick 6.8.99
magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (crash).
network
imagemagick
4.3