Show filters
819 Total Results
Displaying 31-40 of 819
Sort by:
Attacker Value
Unknown
CVE-2023-1906
Disclosure Date: April 12, 2023 (last updated February 24, 2025)
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
0
Attacker Value
Unknown
CVE-2023-29171
Disclosure Date: April 07, 2023 (last updated February 24, 2025)
Unauth. Reflected Cross-site Scripting (XSS) vulnerability in Magic Post Thumbnail plugin <= 4.1.10 versions.
0
Attacker Value
Unknown
CVE-2023-1289
Disclosure Date: March 23, 2023 (last updated February 24, 2025)
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G.
0
Attacker Value
Unknown
CVE-2022-47592
Disclosure Date: March 20, 2023 (last updated February 24, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability in Dmytriy.Cooperman MagicForm plugin <= 0.1 versions.
0
Attacker Value
Unknown
CVE-2022-44267
Disclosure Date: February 06, 2023 (last updated February 24, 2025)
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.
0
Attacker Value
Unknown
CVE-2022-1270
Disclosure Date: September 28, 2022 (last updated February 24, 2025)
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
0
Attacker Value
Unknown
CVE-2022-3213
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.
0
Attacker Value
Unknown
CVE-2022-1115
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.
0
Attacker Value
Unknown
CVE-2022-0284
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.
0
Attacker Value
Unknown
CVE-2021-3574
Disclosure Date: August 26, 2022 (last updated February 24, 2025)
A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.
0