Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
DLA-731-1
No affected components available
imagemagick - security update
Measures severity based on intrinsic characteristics of the vulnerability, independent of environment.
No exploitation activity has been observed at this time. Continue routine monitoring.
The exploit probability is low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
- CVE-2014-9805Upstream
- CVE-2014-9806Upstream
- CVE-2014-9807Upstream
- CVE-2014-9808Upstream
- CVE-2014-9809Upstream
- CVE-2014-9810Upstream
- CVE-2014-9811Upstream
- CVE-2014-9812Upstream
- CVE-2014-9813Upstream
- CVE-2014-9814Upstream
- CVE-2014-9815Upstream
- CVE-2014-9816Upstream
- CVE-2014-9817Upstream
- CVE-2014-9818Upstream
- CVE-2014-9819Upstream
- CVE-2014-9821Upstream
- CVE-2014-9822Upstream
- CVE-2014-9823Upstream
- CVE-2014-9824Upstream
- CVE-2014-9826Upstream
- CVE-2014-9828Upstream
- CVE-2014-9829Upstream
- CVE-2014-9830Upstream
- CVE-2014-9831Upstream
- CVE-2014-9832Upstream
- CVE-2014-9833Upstream
- CVE-2014-9834Upstream
- CVE-2014-9835Upstream
- CVE-2014-9836Upstream
- CVE-2014-9837Upstream
- CVE-2014-9838Upstream
- CVE-2014-9839Upstream
- CVE-2014-9840Upstream
- CVE-2014-9843Upstream
- CVE-2014-9844Upstream
- CVE-2014-9845Upstream
- CVE-2014-9846Upstream
- CVE-2014-9847Upstream
- CVE-2014-9848Upstream
- CVE-2014-9849Upstream
- CVE-2014-9851Upstream
- CVE-2014-9853Upstream
- CVE-2014-9854Upstream
- CVE-2014-9907Upstream
- CVE-2015-8957Upstream
- CVE-2015-8958Upstream
- CVE-2015-8959Upstream
- CVE-2016-10046
Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
Upstream, EPSS 1.97% - CVE-2016-10048
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.
Upstream, EPSS 6.53% - CVE-2016-10050
Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.
Upstream, EPSS 2.02% - CVE-2016-10051
Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
Upstream, EPSS 1.85% - CVE-2016-10052
Buffer overflow in the WriteProfile function in coders/jpeg.c in ImageMagick before 6.9.5-6 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
Upstream, EPSS 2.02% - CVE-2016-10054
Buffer overflow in the WriteMAPImage function in coders/map.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
Upstream, EPSS 1.71% - CVE-2016-10055
Buffer overflow in the WritePDBImage function in coders/pdb.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
Upstream, EPSS 1.71% - CVE-2016-10056
Buffer overflow in the sixel_decode function in coders/sixel.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
Upstream, EPSS 1.77% - CVE-2016-10057
Buffer overflow in the WriteGROUP4Image function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
Upstream, EPSS 1.71% - CVE-2016-4562
The DrawDashPolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles calculations of certain vertices integer data, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
Upstream, EPSS 2.58% - CVE-2016-4564
The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to locate the next token, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
Upstream, EPSS 3.49% - CVE-2016-5010
coders/tiff.c in ImageMagick before 6.9.5-3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF file.
Upstream, EPSS 2.12% - CVE-2016-5687
The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-bounds read.
Upstream, EPSS 4.78% - CVE-2016-5688
The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.
Upstream, EPSS 4.82% - CVE-2016-5689
The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of NULL pointer checks.
Upstream, EPSS 5.45% - CVE-2016-5690
The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact via vectors involving the for statement in computing the pixel scaling table.
Upstream, EPSS 5.45% - CVE-2016-5691
The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixel.blue.
Upstream, EPSS 5.45% - CVE-2016-5841
Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.
Upstream, EPSS 13.39% - CVE-2016-5842
MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.
Upstream, EPSS 6.46% - CVE-2016-6491
Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and crash) via a crafted image.
Upstream, EPSS 5.02% - CVE-2016-6823
Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.
Upstream, EPSS 4.88% - CVE-2016-7101
The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large row value in an sgi file.
Upstream, EPSS 2.74% - CVE-2016-7514Upstream
- CVE-2016-7515Upstream
- CVE-2016-7516Upstream
- CVE-2016-7517Upstream
- CVE-2016-7518Upstream
- CVE-2016-7519Upstream
- CVE-2016-7520Upstream
- CVE-2016-7521Upstream
- CVE-2016-7522Upstream
- CVE-2016-7523Upstream
- CVE-2016-7524Upstream
- CVE-2016-7526Upstream
- CVE-2016-7527Upstream
- CVE-2016-7528Upstream
- CVE-2016-7529Upstream
- CVE-2016-7530Upstream
- CVE-2016-7531Upstream
- CVE-2016-7532Upstream
- CVE-2016-7533Upstream
- CVE-2016-7534Upstream
- CVE-2016-7535Upstream
- CVE-2016-7536Upstream
- CVE-2016-7537
MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted PDB file.
Upstream, EPSS 3.32% - CVE-2016-7538Upstream
- CVE-2016-7539
Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
Upstream, EPSS 4.87% - EUVD-2014-9610Upstream
- EUVD-2014-9611Upstream
- EUVD-2014-9612Upstream
- EUVD-2014-9613Upstream
- EUVD-2014-9614Upstream
- EUVD-2014-9615Upstream
- EUVD-2014-9616Upstream
- EUVD-2014-9617Upstream
- EUVD-2014-9618Upstream
- EUVD-2014-9619Upstream
- EUVD-2014-9620Upstream
- EUVD-2014-9621Upstream
- EUVD-2014-9622Upstream
- EUVD-2014-9623Upstream
- EUVD-2014-9624Upstream
- EUVD-2014-9626Upstream
- EUVD-2014-9627Upstream
- EUVD-2014-9628Upstream
- EUVD-2014-9629Upstream
- EUVD-2014-9631Upstream
- EUVD-2014-9633Upstream
- EUVD-2014-9634Upstream
- EUVD-2014-9635Upstream
- EUVD-2014-9636Upstream
- EUVD-2014-9637Upstream
- EUVD-2014-9638Upstream
- EUVD-2014-9639Upstream
- EUVD-2014-9640Upstream
- EUVD-2014-9641Upstream
- EUVD-2014-9642Upstream
- EUVD-2014-9643Upstream
- EUVD-2014-9644Upstream
- EUVD-2014-9645Upstream
- EUVD-2014-9648Upstream
- EUVD-2014-9649Upstream
- EUVD-2014-9650Upstream
- EUVD-2014-9651Upstream
- EUVD-2014-9652Upstream
- EUVD-2014-9653Upstream
- EUVD-2014-9654Upstream
- EUVD-2014-9656Upstream
- EUVD-2014-9658Upstream
- EUVD-2014-9659Upstream
- EUVD-2014-9712Upstream
- EUVD-2015-8813Upstream
- EUVD-2015-8814Upstream
- EUVD-2015-8815Upstream
- EUVD-2016-1240Upstream
- EUVD-2016-1242Upstream
- EUVD-2016-1244Upstream
- EUVD-2016-1245Upstream
- EUVD-2016-1246Upstream
- EUVD-2016-1248Upstream
- EUVD-2016-1249Upstream
- EUVD-2016-1250Upstream
- EUVD-2016-1251Upstream
- EUVD-2016-5549Upstream
- EUVD-2016-5551Upstream
- EUVD-2016-5969Upstream
- EUVD-2016-6630Upstream
- EUVD-2016-6631Upstream
- EUVD-2016-6632Upstream
- EUVD-2016-6633Upstream
- EUVD-2016-6634Upstream
- EUVD-2016-6776Upstream
- EUVD-2016-6777Upstream
- EUVD-2016-7413Upstream
- EUVD-2016-7708Upstream
- EUVD-2016-7981Upstream
- EUVD-2016-8386Upstream
- EUVD-2016-8367Upstream
- EUVD-2016-8368Upstream
- EUVD-2016-8369Upstream
- EUVD-2016-8370Upstream
- EUVD-2016-8371Upstream
- EUVD-2016-8372Upstream
- EUVD-2016-8373Upstream
- EUVD-2016-8374Upstream
- EUVD-2016-8375Upstream
- EUVD-2016-8376Upstream
- EUVD-2016-8377Upstream
- EUVD-2016-8379Upstream
- EUVD-2016-8380Upstream
- EUVD-2016-8381Upstream
- EUVD-2016-8382Upstream
- EUVD-2016-8383Upstream
- EUVD-2016-8384Upstream
- EUVD-2016-8385Upstream
- EUVD-2016-8387Upstream
- EUVD-2016-8388Upstream
- EUVD-2016-8389Upstream
- EUVD-2016-8390Upstream
- EUVD-2016-8391Upstream
- EUVD-2016-8392Upstream
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard