CVE-2017-13144
- EPSS 0.24%
- Veröffentlicht 23.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, as demonstrated by use of the mpc coder.
CVE-2017-13145
- EPSS 1.33%
- Veröffentlicht 23.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.
CVE-2017-13146
- EPSS 0.46%
- Veröffentlicht 23.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.c.
CVE-2017-13131
- EPSS 0.43%
- Veröffentlicht 23.08.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.6-8, a memory leak vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (memory consumption in NewLinkedList in MagickCore/linked-list.c) via a crafted file.
CVE-2017-13132
- EPSS 0.25%
- Veröffentlicht 23.08.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.6-8, the WritePDFImage function in coders/pdf.c operates on an incorrect data structure in the "dump uncompressed PseudoColor packets" step, which allows attackers to cause a denial of service (assertion failure in WriteBlobStream ...
CVE-2017-13133
- EPSS 0.45%
- Veröffentlicht 23.08.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.6-8, the load_level function in coders/xcf.c lacks offset validation, which allows attackers to cause a denial of service (load_tile memory exhaustion) via a crafted file.
CVE-2017-13134
- EPSS 1.35%
- Veröffentlicht 23.08.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.6-6 and GraphicsMagick 1.3.26, a heap-based buffer over-read was found in the function SFWScan in coders/sfw.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-13058
- EPSS 0.46%
- Veröffentlicht 22.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WritePCXImage in coders/pcx.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-13059
- EPSS 0.46%
- Veröffentlicht 22.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WriteOneJNGImage in coders/png.c, which allows attackers to cause a denial of service (WriteJNGImage memory consumption) via a crafted file.
CVE-2017-13060
- EPSS 0.46%
- Veröffentlicht 22.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.