Imagemagick
808 known vulnerabilities
Top Products
A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.
A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by Im
A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagic
A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed
A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by Imag
A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick
In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-priva
A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an attacker who submit
A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a crafted file that is processed by ImageMagick
A floating point math calculation in ScaleAnyToQuantum() of /MagickCore/quantum-private.h could lead to undefined behavi
In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculations can lead to divide-by-zero conditio
in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which
In IntensityCompare() of /magick/quantize.c, there are calls to PixelPacketIntensity() which could return overflowed val
There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be trig
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processe
A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed
A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An attacker who submits a c
In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo()
In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconst
WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an ou
TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:for
There are 4 places in HistogramCompare() in MagickCore/histogram.c where an integer overflow is possible during simple m
The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() becau
In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows f
A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a passwo
A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by Ima
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values ou
Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(),
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by Ima
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by Ima
In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ss
A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by Imag
A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick
WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outsid
In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero co
In IntensityCompare() of /MagickCore/quantize.c, a double value was being casted to int and returned, which in some case
Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of
ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c duri
In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c.
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remot
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attacke
coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted fil
Frequently Asked Questions
How many CVEs affect Imagemagick?
Imagemagick has 808 CVE records in our database, including 35 critical and 216 high severity vulnerabilities.
What are the most severe Imagemagick vulnerabilities?
Imagemagick has 35 critical severity (CVSS 9.0+) and 216 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Imagemagick vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Imagemagick products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Imagemagick Vulnerabilities
CyberStrike scans your infrastructure for Imagemagick vulnerabilities and provides real-time remediation guidance.
Get Started