CVE-2016-8678
- EPSS 0.21%
- Published 15.02.2017 21:59:00
- Last modified 20.04.2025 01:37:25
The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted file. NOTE: the vendor says "This is a Q64 issue and we do not sup...
CVE-2016-8866
- EPSS 0.68%
- Published 15.02.2017 19:59:01
- Last modified 20.04.2025 01:37:25
The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. NOTE: this vulnerability exists because...
CVE-2016-8862
- EPSS 0.81%
- Published 15.02.2017 19:59:00
- Last modified 20.04.2025 01:37:25
The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.0.3.3 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure.
CVE-2016-9298
- EPSS 0.24%
- Published 27.01.2017 22:59:01
- Last modified 20.04.2025 01:37:25
Heap overflow in the WaveletDenoiseImage function in MagickCore/fx.c in ImageMagick before 6.9.6-4 and 7.x before 7.0.3-6 allows remote attackers to cause a denial of service (crash) via a crafted image.
CVE-2016-6823
- EPSS 0.92%
- Published 18.01.2017 17:59:00
- Last modified 20.04.2025 01:37:25
Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.
CVE-2016-7101
- EPSS 0.52%
- Published 18.01.2017 17:59:00
- Last modified 20.04.2025 01:37:25
The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large row value in an sgi file.
CVE-2016-7799
- EPSS 1.3%
- Published 18.01.2017 17:59:00
- Last modified 20.04.2025 01:37:25
MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
CVE-2016-7906
- EPSS 0.47%
- Published 18.01.2017 17:59:00
- Last modified 20.04.2025 01:37:25
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.
CVE-2016-8707
- EPSS 1.95%
- Published 23.12.2016 22:59:00
- Last modified 12.04.2025 10:46:40
An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code ex...
CVE-2016-6520
- EPSS 3.42%
- Published 13.12.2016 15:59:10
- Last modified 12.04.2025 10:46:40
Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.