CVE-2026-105083
- EPSS 0.12%
- Veröffentlicht 03.10.2026 01:11:12
- Zuletzt bearbeitet 06.10.2026 16:00:36
ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the r...
CVE-2026-102635
- EPSS 0.32%
- Veröffentlicht 29.09.2026 17:17:07
- Zuletzt bearbeitet 30.09.2026 21:17:04
ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitial...
CVE-2026-93589
- EPSS 0.29%
- Veröffentlicht 18.09.2026 13:20:03
- Zuletzt bearbeitet 22.09.2026 20:25:55
ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The ...
CVE-2026-93590
- EPSS 0.31%
- Veröffentlicht 18.09.2026 13:20:03
- Zuletzt bearbeitet 22.09.2026 20:25:55
ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, ...
CVE-2026-93588
- EPSS 0.26%
- Veröffentlicht 18.09.2026 13:20:02
- Zuletzt bearbeitet 22.09.2026 20:25:55
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NULL pointer is ...
CVE-2026-93586
- EPSS 0.11%
- Veröffentlicht 18.09.2026 13:20:01
- Zuletzt bearbeitet 22.09.2026 20:25:55
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the aff...
CVE-2026-93587
- EPSS 0.11%
- Veröffentlicht 18.09.2026 13:20:01
- Zuletzt bearbeitet 22.09.2026 20:25:55
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource limit, which...
CVE-2026-86425
- EPSS 0.14%
- Veröffentlicht 07.09.2026 12:53:47
- Zuletzt bearbeitet 09.09.2026 16:37:29
ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a cras...
CVE-2026-86424
- EPSS 0.12%
- Veröffentlicht 07.09.2026 12:53:46
- Zuletzt bearbeitet 19.09.2026 15:17:06
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between pol...
CVE-2026-86422
- EPSS 0.11%
- Veröffentlicht 07.09.2026 12:53:45
- Zuletzt bearbeitet 10.09.2026 16:18:02
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between...