Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
Low

CVE-2023-34152

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
Attacker Value
Unknown

CVE-2023-34153

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
Attacker Value
Unknown

CVE-2023-34151

Disclosure Date: May 30, 2023 (last updated December 21, 2024)
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
Attacker Value
Unknown

CVE-2022-32547

Disclosure Date: June 16, 2022 (last updated October 07, 2023)
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.
Attacker Value
Unknown

CVE-2022-32546

Disclosure Date: June 16, 2022 (last updated October 07, 2023)
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Attacker Value
Unknown

CVE-2021-3596

Disclosure Date: February 24, 2022 (last updated October 07, 2023)
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
Attacker Value
Unknown

CVE-2020-27769

Disclosure Date: May 14, 2021 (last updated November 28, 2024)
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
Attacker Value
Unknown

CVE-2021-20244

Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-20246

Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-20245

Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.