Show filters
648 Total Results
Displaying 1-10 of 648
Sort by:
Attacker Value
Low

CVE-2023-34152

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
Attacker Value
High

CVE-2022-44268

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
Attacker Value
Unknown

CVE-2024-41817

Disclosure Date: July 29, 2024 (last updated September 12, 2024)
ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.
Attacker Value
Unknown

CVE-2024-34790

Disclosure Date: June 03, 2024 (last updated June 03, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hans van Eijsden,niwreg ImageMagick Sharpen Resized Images allows Stored XSS.This issue affects ImageMagick Sharpen Resized Images: from n/a through 1.1.7.
0
Attacker Value
Unknown

CVE-2023-5341

Disclosure Date: November 19, 2023 (last updated April 25, 2024)
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
Attacker Value
Unknown

CVE-2022-2441

Disclosure Date: October 20, 2023 (last updated October 28, 2023)
The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to run arbitrary commands leading to remote command execution, granted they can trick a site administrator into performing an action such as clicking on a link. This makes it possible for an attacker to create and or modify files hosted on the server which can easily grant attackers backdoor access to the affected server.
Attacker Value
Unknown

CVE-2023-3428

Disclosure Date: October 04, 2023 (last updated April 25, 2024)
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
Attacker Value
Unknown

CVE-2022-48541

Disclosure Date: August 22, 2023 (last updated March 16, 2024)
A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.
Attacker Value
Unknown

CVE-2021-40211

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c.
Attacker Value
Unknown

CVE-2023-39978

Disclosure Date: August 08, 2023 (last updated December 01, 2023)
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.