CVE-2026-61871
- EPSS 0.23%
- Veröffentlicht 15.07.2026 11:25:54
- Zuletzt bearbeitet 15.07.2026 18:20:21
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.
CVE-2026-61868
- EPSS 0.22%
- Veröffentlicht 15.07.2026 11:25:53
- Zuletzt bearbeitet 15.07.2026 18:20:21
ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).
CVE-2026-61867
- EPSS 0.1%
- Veröffentlicht 15.07.2026 11:25:52
- Zuletzt bearbeitet 15.07.2026 18:20:21
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.
CVE-2026-61865
- EPSS 0.1%
- Veröffentlicht 15.07.2026 11:25:51
- Zuletzt bearbeitet 15.07.2026 18:20:21
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.
CVE-2026-61866
- EPSS 0.19%
- Veröffentlicht 15.07.2026 11:25:51
- Zuletzt bearbeitet 16.07.2026 03:01:45
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.
CVE-2026-61864
- EPSS 0.1%
- Veröffentlicht 15.07.2026 11:25:50
- Zuletzt bearbeitet 15.07.2026 18:20:21
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released.
CVE-2026-61862
- EPSS 0.11%
- Veröffentlicht 15.07.2026 11:25:49
- Zuletzt bearbeitet 15.07.2026 18:20:21
ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read pas...
CVE-2026-61863
- EPSS 0.19%
- Veröffentlicht 15.07.2026 11:25:49
- Zuletzt bearbeitet 16.07.2026 20:01:21
ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.
CVE-2026-61860
- EPSS 0.22%
- Veröffentlicht 15.07.2026 11:25:48
- Zuletzt bearbeitet 15.07.2026 18:20:21
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processi...
CVE-2026-61464
- EPSS 0.09%
- Veröffentlicht 15.07.2026 11:25:47
- Zuletzt bearbeitet 15.07.2026 18:20:21
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.