CVE-2017-11360
- EPSS 0.38%
- Veröffentlicht 17.07.2017 13:18:21
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ReadRLEImage function in coders\rle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value.
CVE-2017-11310
- EPSS 0.39%
- Veröffentlicht 13.07.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The read_user_chunk_callback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulnerabilities via crafted PNG files.
CVE-2017-11188
- EPSS 0.37%
- Veröffentlicht 12.07.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted DPX file, related to lack of an EOF check.
CVE-2017-11170
- EPSS 0.35%
- Veröffentlicht 11.07.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ReadTGAImage function in coders\tga.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via invalid colors data in the header of a TGA or VST file.
CVE-2017-11166
- EPSS 0.14%
- Veröffentlicht 10.07.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ReadXWDImage function in coders\xwd.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted length (number of color-map entries) field in the header of an XWD file.
CVE-2017-11141
- EPSS 0.5%
- Veröffentlicht 10.07.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call.
CVE-2017-10995
- EPSS 0.43%
- Veröffentlicht 07.07.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.
CVE-2017-10928
- EPSS 1.05%
- Veröffentlicht 05.07.2017 11:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mis...
CVE-2017-9499
- EPSS 0.32%
- Veröffentlicht 07.06.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9500
- EPSS 0.43%
- Veröffentlicht 07.06.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.