Magick.NET-Q16-HDRI-x86
NuGet159 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Magick.NET-Q16-HDRI-x86page 3 of 4
- CVE-2026-47166MEDIUMCVSS 5.7EG 5.7✓ Fixed in 14.12.02026-05-22
vulnerable: 10.0.0 ... 9.1.2 (210 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in…
- CVE-2026-48724MEDIUMCVSS 5.5EG 5.5✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg dithering method it will cause a negative heap buffer over-write. T…
- CVE-2026-48733MEDIUMCVSS 4.7EG 4.7✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinite loop in the subimage-search operation can happen when using a crafted image. This issue ha…
- CVE-2026-48734MEDIUMCVSS 5.5EG 5.5✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This …
- CVE-2026-48994MEDIUMCVSS 5.9EG 5.9✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit …
- CVE-2026-49218HIGHCVSS 7.5EG 7.5✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cau…
- CVE-2026-49219MEDIUMCVSS 5.5EG 5.5✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a secu…
- CVE-2026-53460HIGHCVSS 7.5EG 7.5✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory cond…
- CVE-2026-53461HIGHCVSS 7.5EG 7.5✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. …
- CVE-2026-53462MEDIUMCVSS 5.9EG 5.9✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when an allocation fails in CheckPrimitiveExtent this can result in a heap-use-after-free and result i…
- CVE-2026-53463MEDIUMCVSS 4.3EG 4.3✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when passing incorrect arguments in the distort operation a null pointer deference will occur. This is…
- CVE-2026-53464MEDIUMCVSS 4.0EG 4.0✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched …
- CVE-2026-53465MEDIUMCVSS 6.2EG 6.2✓ Fixed in 14.14.02026-06-10
vulnerable: 10.0.0 ... 9.1.2 (213 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has be…
- CVE-2026-53466MEDIUMCVSS 6.5EG 6.5✓ Fixed in 14.15.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is rea…
- CVE-2026-53467MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.15.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixe…
- CVE-2026-55510MEDIUMCVSS 5.5EG 5.5✓ Fixed in 14.15.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free w…
- CVE-2026-55594MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.15.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provi…
- CVE-2026-55595MEDIUMCVSS 4.7EG 4.7✓ Fixed in 14.15.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This …
- CVE-2026-55597MEDIUMCVSS 5.5EG 5.5✓ Fixed in 14.15.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed i…
- CVE-2026-55628MEDIUMCVSS 5.5EG 5.5✓ Fixed in 14.15.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to pat…
- CVE-2026-56361HIGHCVSS 7.1EG 7.1✓ Fixed in 14.12.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (210 versions)
ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory…
- CVE-2026-56362MEDIUMCVSS 4.2EG 4.2✓ Fixed in 14.10.32026-07-08
vulnerable: 10.0.0 ... 9.1.2 (206 versions)
ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation…
- CVE-2026-56363LOWCVSS 3.3EG 3.3✓ Fixed in 14.12.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (210 versions)
ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting …
- CVE-2026-56364LOWCVSS 1.9EG 1.9✓ Fixed in 14.10.22026-07-01
vulnerable: 10.0.0 ... 9.1.2 (205 versions)
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache …
- CVE-2026-56365MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.12.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (210 versions)
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.
- CVE-2026-56366MEDIUMCVSS 6.5EG 6.5✓ Fixed in 14.11.12026-07-10
vulnerable: 10.0.0 ... 9.1.2 (209 versions)
ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service…
- CVE-2026-56367CRITICALCVSS 9.1EG 9.1✓ Fixed in 14.10.32026-06-21
vulnerable: 10.0.0 ... 9.1.2 (206 versions)
ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. Processing a crafted PSB …
- CVE-2026-56368HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-25
vulnerable: 10.0.0 ... 9.1.2 (206 versions)
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing m…
- CVE-2026-56369LOWCVSS 3.7EG 3.7✓ Fixed in 14.12.02026-07-01
vulnerable: 10.0.0 ... 9.1.2 (210 versions)
ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information fro…
- CVE-2026-56370HIGHCVSS 7.8EG 7.8✓ Fixed in 14.12.02026-04-14
vulnerable: 10.0.0 ... 9.1.2 (210 versions)
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed c…
- CVE-2026-56371MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.10.32026-06-23
vulnerable: 10.0.0 ... 9.1.2 (206 versions)
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each t…
- CVE-2026-56372CRITICALCVSS 9.1EG 9.1✓ Fixed in 14.12.02026-07-11
vulnerable: 10.0.0 ... 9.1.2 (210 versions)
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposin…
- CVE-2026-56373MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.10.32026-07-10
vulnerable: 10.0.0 ... 9.1.2 (206 versions)
ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or w…
- CVE-2026-56374HIGHCVSS 7.1EG 7.1✓ Fixed in 14.12.02026-07-08
vulnerable: 10.0.0 ... 9.1.2 (210 versions)
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image file…
- CVE-2026-56375LOWCVSS 3.3EG 3.3✓ Fixed in 14.11.12026-07-15
vulnerable: 10.0.0 ... 9.1.2 (209 versions)
ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service.
- CVE-2026-56376LOWCVSS 3.3EG 3.7✓ Fixed in 14.10.32026-06-23
vulnerable: 10.0.0 ... 9.1.2 (206 versions)
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image fi…
- CVE-2026-56378HIGHCVSS 8.2EG 8.2✓ Fixed in 14.10.32026-06-21
vulnerable: 10.0.0 ... 9.1.2 (206 versions)
ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of …
- CVE-2026-56379MEDIUMCVSS 5.5EG 5.5✓ Fixed in 14.10.32026-06-23
vulnerable: 10.0.0 ... 9.1.2 (206 versions)
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Gra…
- CVE-2026-61464LOWCVSS 1.8EG 1.8✓ Fixed in 14.15.02026-07-15
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.
- CVE-2026-61465MEDIUMCVSS 6.5EG 6.5✓ Fixed in 14.15.02026-07-11
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than pe…
- CVE-2026-61857HIGHCVSS 7.5EG 7.5✓ Fixed in 14.15.02026-07-11
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cau…
- CVE-2026-61858MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.15.02026-07-11
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions throu…
- CVE-2026-61859LOWCVSS 3.3EG 3.3✓ Fixed in 14.15.02026-07-15
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the conf…
- CVE-2026-61860LOWCVSS 3.7EG 3.7✓ Fixed in 14.15.02026-07-15
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during ima…
- CVE-2026-61861HIGHCVSS 7.5EG 7.5✓ Fixed in 14.15.02026-07-11
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, pot…
- CVE-2026-61862LOWCVSS 2.9EG 2.9✓ Fixed in 14.15.02026-07-15
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printe…
- CVE-2026-61863HIGHCVSS 7.5EG 7.5✓ Fixed in 14.15.02026-07-15
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.
- CVE-2026-61864LOWCVSS 2.9EG 2.9✓ Fixed in 14.15.02026-07-15
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released.
- CVE-2026-61865LOWCVSS 2.9EG 2.9✓ Fixed in 14.15.02026-07-15
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.
- CVE-2026-61866HIGHCVSS 7.5EG 7.5✓ Fixed in 14.15.02026-07-15
vulnerable: 10.0.0 ... 9.1.2 (214 versions)
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.
Check whether Magick.NET-Q16-HDRI-x86 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Magick.NET-Q16-HDRI-x86 CVEs against the assets you own.
Start Free Scan →