Search: "imagemagick"

795 CVEs found

lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w an...

Published: 2006-09-29
Products: 3
Vendors:
andreas_gohr
CVE-2006-5456
5.1 MEDIUM

Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that i...

Published: 2006-10-23
Products: 8
Vendors:
imagemagick graphicsmagick

Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image.

Published: 2006-11-22
Products: 6
Vendors:
canonical debian imagemagick
CVE-2007-0835
6.5 MEDIUM

admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (";" semicolon) in the "Command line ...

Published: 2007-02-08
Products: 1
Vendors:
coppermine

Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled b...

Published: 2007-02-12
Products: 2
Vendors:
imagemagick graphicsmagick

Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a...

Published: 2007-03-24
Products: 6
Vendors:
canonical x.org debian
CVE-2007-1797
6.8 MEDIUM

Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage functi...

Published: 2007-04-02
Products: 30
Vendors:
imagemagick
CVE-2007-2721
4.3 MEDIUM

The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corr...

Published: 2007-05-16
Products: 1
Vendors:
jasper_jpeg-2000
CVE-2007-4985
4.3 MEDIUM

ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlob...

Published: 2007-09-24
Products: 57
Vendors:
imagemagick
CVE-2007-4986
6.8 MEDIUM

Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which...

Published: 2007-09-24
Products: 57
Vendors:
imagemagick

Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writin...

Published: 2007-09-24
Products: 57
Vendors:
imagemagick

Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers ...

Published: 2007-09-24
Products: 4
Vendors:
canonical imagemagick
CVE-2008-0506
6.8 MEDIUM

include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via...

Published: 2008-01-31
Products: 1
Vendors:
coppermine
CVE-2008-1096
6.8 MEDIUM

The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or p...

Published: 2008-03-05
Products: 10
Vendors:
imagemagick
CVE-2008-1097
6.8 MEDIUM

Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attack...

Published: 2008-03-05
Products: 10
Vendors:
imagemagick

Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary ...

Published: 2009-06-02
Products: 1
Vendors:
imagemagick
CVE-2010-1598
6.8 MEDIUM

phpThumb.php in phpThumb() 1.7.9 and possibly other versions, when ImageMagick is installed, allows remote attackers to execute arbitrary commands via the fltr[] parameter, as discovered in the wild i...

Published: 2010-04-29
Products: 1
Vendors:
silisoftware

tif_getimage.c in LibTIFF 3.9.0 and 3.9.2 on 64-bit platforms, as used in ImageMagick, does not properly perform vertical flips, which allows remote attackers to cause a denial of service (application...

Published: 2010-07-02
Products: 2
Vendors:
libtiff
CVE-2010-2595
4.3 MEDIUM

The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ImageMagick, does not properly handle invalid ReferenceBlackWhite values, which allows remote attackers to cause a denial of service ...

Published: 2010-07-02
Products: 2
Vendors:
libtiff
CVE-2010-4167
6.9 MEDIUM

Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration f...

Published: 2010-11-22
Products: 326
Vendors:
imagemagick