Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

DLA-1401-1

Published Jun 27, 2018·Last modified Mar 9, 2026
Affected Components(0)

No affected components available

Description

graphicsmagick - security update

Risk Scores
Base Score
0.0

Measures severity based on intrinsic characteristics of the vulnerability, independent of environment.

Threat Intelligence
0.0

No exploitation activity has been observed at this time. Continue routine monitoring.

EPSS
76.90%

The exploit probability is very high. The vulnerability is very likely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Related Vulnerabilities
  • CVE-2016-3716

    The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.

    UpstreamEPSS 11.3%
  • CVE-2016-3717

    The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

    UpstreamEPSS 20.4%
  • CVE-2016-3718

    The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

    UpstreamEPSS 76.9%
  • CVE-2016-5241
    Upstream
  • CVE-2016-7446
    Upstream
  • CVE-2016-7447
    Upstream
  • CVE-2016-7448
    Upstream
  • CVE-2016-7449
    Upstream
  • CVE-2017-11636
    Upstream
  • CVE-2017-11643
    Upstream
  • CVE-2017-12937
    Upstream
  • CVE-2017-13063
    Upstream
  • CVE-2017-13064
    Upstream
  • CVE-2017-13065
    Upstream
  • CVE-2017-13134

    In ImageMagick 7.0.6-6 and GraphicsMagick 1.3.26, a heap-based buffer over-read was found in the function SFWScan in coders/sfw.c, which allows attackers to cause a denial of service via a crafted file.

    UpstreamEPSS 2.0%
  • CVE-2017-14314
    Upstream
  • CVE-2017-14733
    Upstream
  • CVE-2017-16353
    Upstream
  • CVE-2017-16669
    Upstream
  • CVE-2017-17498
    Upstream
  • CVE-2017-17500
    Upstream
  • CVE-2017-17501
    Upstream
  • CVE-2017-17502
    Upstream
  • CVE-2017-17503
    Upstream
  • CVE-2017-17782
    Upstream
  • CVE-2017-17912
    Upstream
  • CVE-2017-17915
    Upstream
  • EUVD-2016-4737
    Upstream
  • EUVD-2016-4738
    Upstream
  • EUVD-2016-4739
    Upstream
  • EUVD-2016-6192
    Upstream
  • EUVD-2016-8299
    Upstream
  • EUVD-2016-8300
    Upstream
  • EUVD-2016-8301
    Upstream
  • EUVD-2016-8302
    Upstream
  • EUVD-2017-3248
    Upstream
  • EUVD-2017-3255
    Upstream
  • EUVD-2017-4461
    Upstream
  • EUVD-2017-4581
    Upstream
  • EUVD-2017-4582
    Upstream
  • EUVD-2017-4583
    Upstream
  • EUVD-2017-4651
    Upstream
  • EUVD-2017-5817
    Upstream
  • EUVD-2017-6230
    Upstream
  • EUVD-2017-7548
    Upstream
  • EUVD-2017-7853
    Upstream
  • EUVD-2017-8659
    Upstream
  • EUVD-2017-8661
    Upstream
  • EUVD-2017-8662
    Upstream
  • EUVD-2017-8663
    Upstream
  • EUVD-2017-8664
    Upstream
  • EUVD-2017-8933
    Upstream
  • EUVD-2017-9055
    Upstream
  • EUVD-2017-9058
    Upstream
Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard