Search CVE reports


Toggle filters

631 – 640 of 737 results


CVE-2016-4564

Medium priority

Some fixes available 4 of 5

The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to locate the next token, which allows remote attackers to cause a denial of service...

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2016-4563

Medium priority

Some fixes available 4 of 5

The TraceStrokePolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles the relationship between the BezierQuantum value and certain strokes data, which allows remote attackers to cause...

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2016-4562

Medium priority

Some fixes available 4 of 5

The DrawDashPolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles calculations of certain vertices integer data, which allows remote attackers to cause a denial of service (buffer...

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2016-5118

Medium priority

Some fixes available 11 of 16

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

2 affected packages

graphicsmagick, imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
imagemagick Fixed
Show less packages

CVE-2016-3718

Medium priority

Some fixes available 11 of 16

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

2 affected packages

graphicsmagick, imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
imagemagick Fixed
Show less packages

CVE-2016-3717

Medium priority

Some fixes available 11 of 16

The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

2 affected packages

graphicsmagick, imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
imagemagick Fixed
Show less packages

CVE-2016-3716

Medium priority

Some fixes available 11 of 16

The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.

2 affected packages

graphicsmagick, imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
imagemagick Fixed
Show less packages

CVE-2016-3715

Medium priority

Some fixes available 11 of 16

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

2 affected packages

graphicsmagick, imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
imagemagick Fixed
Show less packages

CVE-2016-3714

Medium priority

Some fixes available 11 of 16

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a...

2 affected packages

imagemagick, graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Fixed
graphicsmagick Not affected
Show less packages

CVE-2015-8903

Medium priority

Some fixes available 2 of 3

The ReadVICARImage function in coders/vicar.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted VICAR file.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages