CVE-2026-61859
- EPSS 0.12%
- Veröffentlicht 15.07.2026 11:25:47
- Zuletzt bearbeitet 16.07.2026 20:01:34
ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured secu...
CVE-2026-56375
- EPSS 0.11%
- Veröffentlicht 15.07.2026 11:25:30
- Zuletzt bearbeitet 15.07.2026 18:20:21
ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service.
CVE-2026-61861
- EPSS 0.32%
- Veröffentlicht 11.07.2026 13:01:09
- Zuletzt bearbeitet 13.07.2026 22:09:54
ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially en...
CVE-2026-61870
- EPSS 0.19%
- Veröffentlicht 11.07.2026 13:01:09
- Zuletzt bearbeitet 13.07.2026 22:07:31
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of s...
CVE-2026-61858
- EPSS 0.25%
- Veröffentlicht 11.07.2026 13:01:08
- Zuletzt bearbeitet 14.07.2026 15:17:09
ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG...
CVE-2026-61465
- EPSS 0.17%
- Veröffentlicht 11.07.2026 13:01:07
- Zuletzt bearbeitet 14.07.2026 15:17:09
ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by ...
CVE-2026-61857
- EPSS 0.27%
- Veröffentlicht 11.07.2026 13:01:07
- Zuletzt bearbeitet 13.07.2026 22:11:46
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause applicat...
CVE-2026-56372
- EPSS 0.2%
- Veröffentlicht 11.07.2026 13:00:58
- Zuletzt bearbeitet 13.07.2026 22:18:43
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive...
CVE-2026-56366
- EPSS 0.17%
- Veröffentlicht 10.07.2026 13:57:58
- Zuletzt bearbeitet 14.07.2026 02:16:56
ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through re...
CVE-2026-56373
- EPSS 0.23%
- Veröffentlicht 10.07.2026 13:57:58
- Zuletzt bearbeitet 13.07.2026 15:15:51
ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a sing...