Show filters
648 Total Results
Displaying 1-10 of 648
Sort by:
Attacker Value
Low
CVE-2023-34152
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
2
Attacker Value
High
CVE-2022-44268
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
1
Attacker Value
Unknown
CVE-2024-41817
Disclosure Date: July 29, 2024 (last updated September 12, 2024)
ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.
0
Attacker Value
Unknown
CVE-2024-34790
Disclosure Date: June 03, 2024 (last updated June 03, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hans van Eijsden,niwreg ImageMagick Sharpen Resized Images allows Stored XSS.This issue affects ImageMagick Sharpen Resized Images: from n/a through 1.1.7.
0
Attacker Value
Unknown
CVE-2023-5341
Disclosure Date: November 19, 2023 (last updated April 25, 2024)
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
0
Attacker Value
Unknown
CVE-2022-2441
Disclosure Date: October 20, 2023 (last updated October 28, 2023)
The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to run arbitrary commands leading to remote command execution, granted they can trick a site administrator into performing an action such as clicking on a link. This makes it possible for an attacker to create and or modify files hosted on the server which can easily grant attackers backdoor access to the affected server.
0
Attacker Value
Unknown
CVE-2023-3428
Disclosure Date: October 04, 2023 (last updated April 25, 2024)
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
0
Attacker Value
Unknown
CVE-2022-48541
Disclosure Date: August 22, 2023 (last updated March 16, 2024)
A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.
0
Attacker Value
Unknown
CVE-2021-40211
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c.
0
Attacker Value
Unknown
CVE-2023-39978
Disclosure Date: August 08, 2023 (last updated December 01, 2023)
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
0