Search CVE reports
11 – 20 of 644 results
CVE-2023-34475
Medium priorityA heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write...
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | — | Not affected | Not affected | Not affected |
CVE-2023-34474
Medium priorityA heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error,...
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | — | Not affected | Not affected | Not affected |
CVE-2023-3195
Medium priorityA stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a...
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | Fixed | Fixed | Not affected | Not affected |
CVE-2023-2157
Medium priorityA heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing.
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | — | Not affected | Not affected | Not affected |
CVE-2023-34153
Medium priorityA vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | — | Not affected | Not affected | Not affected |
CVE-2023-34152
Medium priorityA vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | — | Ignored | Ignored | Ignored |
CVE-2023-34151
Medium prioritySome fixes available 10 of 11
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | Fixed | Fixed | Fixed | Fixed |
CVE-2023-1906
Low priorityA heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read...
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | Fixed | Fixed | Not affected | Not affected |
CVE-2023-1289
Low priorityA vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation...
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | Fixed | Fixed | Fixed | Not affected |
CVE-2022-44268
Medium prioritySome fixes available 6 of 8
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
1 affected package
imagemagick
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
imagemagick | Not affected | Fixed | Fixed | Fixed |