Vulnerabilidades em ImageMagick

177 resultados
Análise Vexday

Com 134 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, o ImageMagick apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão de ameaças imediatas no momento. No entanto, chama atenção o volume de 48 vulnerabilidades surgidas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes que requer acompanhamento contínuo. O tipo de falha mais frequente é CWE-122 (heap-based buffer overflow), classe de fraqueza que historicamente favorece execução de código e merece atenção prioritária em ambientes que processam imagens de origem não confiável. A CVE mais perigosa ativa no momento, CVE-2025-55298, possui EPSS de 0,041 e é a única com PoC pública disponível, representando o ponto de atenção mais concreto para equipes de remediação.

CVE-2025-69204MEDIUMImageMagick converting a malicious MVG file to SVG caused an integer overflow.EPSS 0.5%CVE-2025-55004HIGHImageMagick: heap-buffer overflow read in MNG magnification with alphaEPSS 0.5%CVE-2026-33908HIGHImageMagick is vulnerable to Stack Overflow in DestroyXMLTree()EPSS 0.5%CVE-2026-25985HIGHMemory allocation with excessive without limits in the internal SVG decoderEPSS 0.5%CVE-2026-45031MEDIUMImageMagick: Policy Bypass in PSD decoderEPSS 0.5%CVE-2026-32636MEDIUMImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crashEPSS 0.5%CVE-2025-53019LOWImageMagick has Memory Leak in magick streamEPSS 0.5%CVE-2026-25986MEDIUMImageMagick has a heap buffer overflow in YUV 4:2:2 decoderEPSS 0.5%CVE-2025-66628HIGHImageMagick is vulnerable to an Integer Overflow in TIM decoder leading to out of bounds read (32-bit only)EPSS 0.5%CVE-2026-26983MEDIUMImageMagick: Invalid MSL <map> can result in a use after freeEPSS 0.4%CVE-2026-24485HIGHImageMagick: Infinite loop vulnerability when parsing a PCD fileEPSS 0.4%CVE-2026-46520HIGHImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensionsEPSS 0.4%CVE-2026-45664MEDIUMImageMagick: Policy Bypass in MNG coder couldEPSS 0.4%CVE-2026-25988MEDIUMImageMagick's MSL image stack index not refreshed, leading to leaked images.EPSS 0.4%CVE-2026-25983MEDIUMImageMagick has Use After Free in MSLStartElement in "coders/msl.c"EPSS 0.4%CVE-2026-33900MEDIUMImageMagick has a Heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit buildsEPSS 0.4%CVE-2026-23952MEDIUMImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image loadEPSS 0.4%CVE-2026-25798MEDIUMImageMagick has NULL Pointer Dereference in ClonePixelCacheRepository via crafted imageEPSS 0.4%CVE-2026-33899MEDIUMImageMagick: Heap BufferOverflow write of single zero byte when parsing XMLEPSS 0.4%CVE-2026-25794HIGHImageMagick has heap-buffer-overflow via signed integer overflow in `WriteUHDRImage` when writing UHDR images with large dimensionsEPSS 0.4%