ImageMagick kayıtları
imagemagick üreticisine ait 812 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %0,4
- Silahlaştırılmış
- 3 · %0,4
- Pre-auth RCE
- 30
- Düzeltme kaydı olan
- %96,2
- Yayından KEV’e ortanca
- 2008 gün
Tekrar eden sınıflar
- CWE-772 Missing Release of Resource after Effective Lifetime127
- CWE-125 Out-of-bounds Read111
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer63
- CWE-190 Integer Overflow or Wraparound45
- CWE-401 Missing Release of Memory after Effective Lifetime42
- CWE-476 NULL Pointer Dereference38
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
812 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
92Hemen | CVE-2016-3714Silahlaştırılmış | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x beforimagemagick · imagemagick · CWE-20 | Yüksek8,4 | KEV | %97,5 | 5 May 2016 |
75Bu hafta | CVE-2016-3718Silahlaştırılmış | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request imagemagick · imagemagick · CWE-918 | Orta5,5 | KEV | %76,7 | 5 May 2016 |
75Bu hafta | CVE-2016-3715Silahlaştırılmış | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted imimagemagick · imagemagick · CWE-552 | Orta5,5 | KEV | %75,3 | 5 May 2016 |
54Planlayın | CVE-2016-5118İstismar yok | The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pgraphicsmagick · graphicsmagick | Kritik9,8 | — | %50,0 | 10 Haz 2016 |
53Planlayın | CVE-2022-44268Kavram kanıtı | ImageMagick 7.1.0-49 is vulnerable to Information Disclosure.imagemagick · imagemagick · CWE-200 | Orta6,5 | — | %89,9 | 6 Şub 2023 |
49Planlayın | CVE-2022-44267Kavram kanıtı | ImageMagick 7.1.0-49 is vulnerable to Denial of Service.imagemagick · imagemagick · CWE-404 | Orta6,5 | — | %76,6 | 6 Şub 2023 |
43Planlayın | CVE-2016-5841İstismar yok | Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation faimagemagick · imagemagick · CWE-190 | Kritik9,8 | — | %13,4 | 13 Ara 2016 |
42Planlayın | CVE-2004-0981İstismar yok | Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain imagimagemagick · imagemagick | Kritik10,0 | — | %5,8 | 9 Şub 2005 |
41Planlayın | CVE-2018-16323Kavram kanıtı | ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel vimagemagick · imagemagick · CWE-200 | Orta6,5 | — | %49,3 | 1 Eyl 2018 |
41Planlayın | CVE-2023-34152Kavram kanıtı | A vulnerability was found in ImageMagick.imagemagick · imagemagick · CWE-20 | Kritik9,8 | — | %8,0 | 30 May 2023 |
41Planlayın | CVE-2017-5511İstismar yok | coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based bimagemagick · imagemagick · CWE-119 | Kritik9,8 | — | %5,5 | 24 Mar 2017 |
41Planlayın | CVE-2016-5690İstismar yok | The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impimagemagick · imagemagick · CWE-476 | Kritik9,8 | — | %5,4 | 13 Ara 2016 |
41Planlayın | CVE-2016-5691İstismar yok | The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack ofimagemagick · imagemagick · CWE-20 | Kritik9,8 | — | %5,4 | 13 Ara 2016 |
41Planlayın | CVE-2016-5689İstismar yok | The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack ofimagemagick · imagemagick · CWE-476 | Kritik9,8 | — | %5,4 | 13 Ara 2016 |
41Planlayın | CVE-2016-10145İstismar yok | Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.imagemagick · imagemagick · CWE-189 | Kritik9,8 | — | %5,4 | 24 Mar 2017 |
40Planlayın | CVE-2012-1185İstismar yok | Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to causeimagemagick · imagemagick · CWE-190 | Yüksek7,8 | — | %29,7 | 5 Haz 2012 |
40Planlayın | CVE-2016-10144İstismar yok | coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.imagemagick · imagemagick · CWE-284 | Kritik9,8 | — | %4,9 | 24 Mar 2017 |
40Planlayın | CVE-2014-9846İstismar yok | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.imagemagick · imagemagick · CWE-119 | Kritik9,8 | — | %4,9 | 20 Mar 2017 |
40Planlayın | CVE-2016-5687İstismar yok | The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecifieimagemagick · imagemagick · CWE-125 | Kritik9,8 | — | %4,8 | 13 Ara 2016 |
40Planlayın | CVE-2014-9847İstismar yok | The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.imagemagick · imagemagick · CWE-119 | Kritik9,8 | — | %4,6 | 20 Mar 2017 |
40Planlayın | CVE-2018-14551İstismar yok | The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption.imagemagick · imagemagick · CWE-787 | Kritik9,8 | — | %4,0 | 23 Tem 2018 |
40Planlayın | CVE-2014-9843İstismar yok | The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.imagemagick · imagemagick · CWE-119 | Kritik9,8 | — | %3,9 | 20 Mar 2017 |
40Planlayın | CVE-2014-9841İstismar yok | The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, reimagemagick · imagemagick · CWE-388 | Kritik9,8 | — | %3,9 | 20 Mar 2017 |
40Planlayın | CVE-2017-13139İstismar yok | In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLimagemagick · imagemagick · CWE-125 | Kritik9,8 | — | %3,8 | 23 Ağu 2017 |
40Planlayın | CVE-2017-18211İstismar yok | In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a primagemagick · imagemagick · CWE-476 | Kritik9,8 | — | %3,8 | 1 Mar 2018 |
- CVE-2016-371492Hemen
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor
YüksekCVSS 8,4KEVSilahlaştırılmışEPSS %97imagemagick · imagemagick5 May 2016
- CVE-2016-371875Bu hafta
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request
OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %77imagemagick · imagemagick5 May 2016
- CVE-2016-371575Bu hafta
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted im
OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %75imagemagick · imagemagick5 May 2016
- CVE-2016-511854Planlayın
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (p
KritikCVSS 9,8İstismar yokEPSS %50graphicsmagick · graphicsmagick10 Haz 2016
- CVE-2022-4426853Planlayın
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure.
OrtaCVSS 6,5Kavram kanıtıEPSS %90imagemagick · imagemagick6 Şub 2023
- CVE-2022-4426749Planlayın
ImageMagick 7.1.0-49 is vulnerable to Denial of Service.
OrtaCVSS 6,5Kavram kanıtıEPSS %77imagemagick · imagemagick6 Şub 2023
- CVE-2016-584143Planlayın
Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fa
KritikCVSS 9,8İstismar yokEPSS %13imagemagick · imagemagick13 Ara 2016
- CVE-2004-098142Planlayın
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain imag
KritikCVSS 10,0İstismar yokEPSS %6imagemagick · imagemagick9 Şub 2005
- CVE-2018-1632341Planlayın
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel v
OrtaCVSS 6,5Kavram kanıtıEPSS %49imagemagick · imagemagick1 Eyl 2018
- CVE-2023-3415241Planlayın
A vulnerability was found in ImageMagick.
KritikCVSS 9,8Kavram kanıtıEPSS %8imagemagick · imagemagick30 May 2023
- CVE-2017-551141Planlayın
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based b
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick24 Mar 2017
- CVE-2016-569041Planlayın
The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified imp
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick13 Ara 2016
- CVE-2016-569141Planlayın
The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick13 Ara 2016
- CVE-2016-568941Planlayın
The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick13 Ara 2016
- CVE-2016-1014541Planlayın
Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick24 Mar 2017
- CVE-2012-118540Planlayın
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause
YüksekCVSS 7,8İstismar yokEPSS %30imagemagick · imagemagick5 Haz 2012
- CVE-2016-1014440Planlayın
coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick24 Mar 2017
- CVE-2014-984640Planlayın
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick20 Mar 2017
- CVE-2016-568740Planlayın
The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecifie
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick13 Ara 2016
- CVE-2014-984740Planlayın
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick20 Mar 2017
- CVE-2018-1455140Planlayın
The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption.
KritikCVSS 9,8İstismar yokEPSS %4imagemagick · imagemagick23 Tem 2018
- CVE-2014-984340Planlayın
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
KritikCVSS 9,8İstismar yokEPSS %4imagemagick · imagemagick20 Mar 2017
- CVE-2014-984140Planlayın
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, re
KritikCVSS 9,8İstismar yokEPSS %4imagemagick · imagemagick20 Mar 2017
- CVE-2017-1313940Planlayın
In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CL
KritikCVSS 9,8İstismar yokEPSS %4imagemagick · imagemagick23 Ağu 2017
- CVE-2017-1821140Planlayın
In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a pr
KritikCVSS 9,8İstismar yokEPSS %4imagemagick · imagemagick1 Mar 2018