CVE-2026-25799
- EPSS 0.02%
- Veröffentlicht 24.02.2026 01:16:14
- Zuletzt bearbeitet 24.02.2026 18:44:52
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a ...
CVE-2026-25637
- EPSS 0.02%
- Veröffentlicht 24.02.2026 01:16:13
- Zuletzt bearbeitet 27.02.2026 14:32:59
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image that results ...
CVE-2026-25638
- EPSS 0.02%
- Veröffentlicht 24.02.2026 01:16:13
- Zuletzt bearbeitet 24.02.2026 17:29:35
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocate...
CVE-2026-25794
- EPSS 0.02%
- Veröffentlicht 24.02.2026 01:16:13
- Zuletzt bearbeitet 24.02.2026 17:28:54
ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the...
CVE-2026-25576
- EPSS 0.01%
- Veröffentlicht 24.02.2026 00:38:34
- Zuletzt bearbeitet 27.02.2026 14:33:55
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when ...
CVE-2026-24485
- EPSS 0.02%
- Veröffentlicht 24.02.2026 00:34:04
- Zuletzt bearbeitet 27.02.2026 14:34:13
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite l...
CVE-2026-24484
- EPSS 0.02%
- Veröffentlicht 24.02.2026 00:31:05
- Zuletzt bearbeitet 27.02.2026 14:37:34
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13...
CVE-2026-24481
- EPSS 0.02%
- Veröffentlicht 24.02.2026 00:29:20
- Zuletzt bearbeitet 24.02.2026 17:42:17
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When pr...
CVE-2025-24293
- EPSS 0.21%
- Veröffentlicht 30.01.2026 20:11:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow f...
CVE-2026-23952
- EPSS 0.02%
- Veröffentlicht 22.01.2026 00:32:52
- Zuletzt bearbeitet 27.02.2026 15:35:07
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags befor...