Vulnerabilities in ImageMagick

177 results
Vexday analysis

Com 134 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, o ImageMagick apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão de ameaças imediatas no momento. No entanto, chama atenção o volume de 48 vulnerabilidades surgidas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes que requer acompanhamento contínuo. O tipo de falha mais frequente é CWE-122 (heap-based buffer overflow), classe de fraqueza que historicamente favorece execução de código e merece atenção prioritária em ambientes que processam imagens de origem não confiável. A CVE mais perigosa ativa no momento, CVE-2025-55298, possui EPSS de 0,041 e é a única com PoC pública disponível, representando o ponto de atenção mais concreto para equipes de remediação.

CVE-2025-55298HIGHImageMagick Format String Bug in InterpretImageFilename leads to arbitrary code executionEPSS 4.4%CVE-2016-7523coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.EPSS 2.6%CVE-2016-7524coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.EPSS 2.2%CVE-2026-46522HIGHImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustionEPSS 1.8%CVE-2019-10131MEDIUMAn off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.cEPSS 1.3%CVE-2025-55154HIGHImageMagick: integer overflows in MNG magnificationEPSS 1.0%CVE-2024-41817HIGHArbitrary Code Execution in `AppImage` version `ImageMagick`EPSS 0.9%CVE-2025-55212LOWImageMagick affected by divide-by-zero in ThumbnailImage via montage -geometry ":" leads to crashEPSS 0.9%CVE-2026-56379CRITICALImageMagick - Command Injection via SVG DecoderEPSS 0.9%CVE-2025-57803HIGHImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflowEPSS 0.8%CVE-2025-53101HIGHImageMagick has Stack Buffer Overflow in image.cEPSS 0.8%CVE-2025-62171MEDIUMImageMagick vulnerable to denial of service via integer overflow in BMP decoder on 32-bit systemsEPSS 0.8%CVE-2025-53015HIGHImageMagick has XMP profile write that triggers hang due to unbounded loopEPSS 0.7%CVE-2026-25965HIGHImageMagick's policy bypass through path traversal allows reading restricted content despite secured policyEPSS 0.7%CVE-2025-53014LOWImageMagick has Heap Buffer Overflow in InterpretImageFilenameEPSS 0.6%CVE-2026-25989HIGHImageMagick has integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoderEPSS 0.6%CVE-2026-23876HIGHHeap buffer overflow with attacker-controlled data in XBM parserEPSS 0.6%CVE-2025-68618MEDIUMMagick's failure to limit the depth of SVG file reads caused a DoS attack.EPSS 0.6%CVE-2026-33901HIGHImageMagick has a Heap Buffer Overflow via MVG decoderEPSS 0.6%CVE-2025-43965LOWIn MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.EPSS 0.5%