Magick.NET-Q16-x64
NuGet151 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Magick.NET-Q16-x64page 1 of 4
- CVE-2023-1289MEDIUMCVSS 5.5EG 5.5✓ Fixed in 13.0.02023-03-23
vulnerable: 10.0.0 ... 9.1.2 (193 versions)
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, gene…
- CVE-2025-53014LOWCVSS 3.7EG 3.7✓ Fixed in 14.7.02025-07-14
vulnerable: 10.0.0 ... 9.1.2 (216 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one…
- CVE-2025-53015HIGHCVSS 7.5EG 7.5✓ Fixed in 14.7.02025-07-14
vulnerable: 10.0.0 ... 9.1.2 (216 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.
- CVE-2025-53019LOWCVSS 3.7EG 3.7✓ Fixed in 14.7.02025-07-14
vulnerable: 10.0.0 ... 9.1.2 (216 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in …
- CVE-2025-53101HIGHCVSS 7.4EG 7.4✓ Fixed in 14.7.02025-07-14
vulnerable: 10.0.0 ... 9.1.2 (216 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in…
- CVE-2025-55004HIGHCVSS 7.6EG 7.6✓ Fixed in 14.8.02025-08-13
vulnerable: 10.0.0 ... 9.1.2 (217 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when…
- CVE-2025-55154HIGHCVSS 8.8EG 8.8✓ Fixed in 14.8.02025-08-13
vulnerable: 10.0.0 ... 9.1.2 (217 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leadi…
- CVE-2025-55160MEDIUMCVSS 6.1EG 6.1✓ Fixed in 14.8.02025-08-13
vulnerable: 10.0.0 ... 9.1.2 (217 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a …
- CVE-2025-55212LOWCVSS 3.7EG 3.7✓ Fixed in 14.8.12025-08-26
vulnerable: 10.0.0 ... 9.1.2 (218 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (":") to montage -geometry leads GetGeometry() to set…
- CVE-2025-55298HIGHCVSS 7.5EG 7.5✓ Fixed in 14.8.12025-08-26
vulnerable: 10.0.0 ... 9.1.2 (218 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user inpu…
- CVE-2025-57807LOWCVSS 3.8EG 3.8✓ Fixed in 14.8.22025-09-05
vulnerable: 10.0.0 ... 9.1.2 (219 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end…
- CVE-2025-62594MEDIUMCVSS 5.5EG 5.52025-10-27
vulnerable: 10.0.0 ... 9.1.2 (221 versions)
ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and division-by-zero in the CLAHEImage function…
- CVE-2025-65955MEDIUMCVSS 6.1EG 6.12025-12-02
vulnerable: 10.0.0 ... 9.1.2 (222 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked wi…
- CVE-2025-68469LOWCVSS 3.3EG 3.3✓ Fixed in 13.2.02025-12-18
vulnerable: 10.0.0 ... 9.1.2 (199 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.
- CVE-2025-68618MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.10.12025-12-30
vulnerable: 10.0.0 ... 9.1.2 (223 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue.
- CVE-2026-22770CRITICALCVSS 9.8EG 9.8✓ Fixed in 14.10.22026-01-20
vulnerable: 10.0.0 ... 9.1.2 (224 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last ele…
- CVE-2026-23874MEDIUMCVSS 5.5EG 5.5✓ Fixed in 14.10.22026-01-20
vulnerable: 10.0.0 ... 9.1.2 (224 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when writing to MSL…
- CVE-2026-23952HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.22026-01-22
vulnerable: 10.0.0 ... 9.1.2 (224 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment>…
- CVE-2026-24481HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handl…
- CVE-2026-24484MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15…
- CVE-2026-24485HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an…
- CVE-2026-25576MEDIUMCVSS 5.5EG 5.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability o…
- CVE-2026-25637MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image th…
- CVE-2026-25638MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources a…
- CVE-2026-25794HIGHCVSS 8.2EG 8.2✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are…
- CVE-2026-25796HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early…
- CVE-2026-25798HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any applicat…
- CVE-2026-25799HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and…
- CVE-2026-25897CRITICALCVSS 9.8EG 9.8✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully cra…
- CVE-2026-25898CRITICALCVSS 9.1EG 9.1✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` befo…
- CVE-2026-25965HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem reso…
- CVE-2026-25966MEDIUMCVSS 5.9EG 5.9✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule intended to prevent reading/writing from standard streams. However, ImageMagick also suppor…
- CVE-2026-25967HIGHCVSS 7.4EG 7.4✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a stack-based buffer overflow exists in the ImageMagick FTXT image reader. A crafted FTXT file can cause out-of-bound…
- CVE-2026-25968CRITICALCVSS 9.8EG 9.8✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fix…
- CVE-2026-25970MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger m…
- CVE-2026-25971MEDIUMCVSS 6.2EG 6.2✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for circular references between two MSLs, leading to a stack overflow. Versions …
- CVE-2026-25982MEDIUMCVSS 6.5EG 6.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap out-of-bounds read vulnerability exists in the `coders/dcm.c` module. When processing DICOM fil…
- CVE-2026-25983CRITICALCVSS 9.8EG 9.8✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The operation element handler replaces and frees …
- CVE-2026-25985HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB o…
- CVE-2026-25986CRITICALCVSS 9.8EG 9.8✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing mal…
- CVE-2026-25987CRITICALCVSS 9.1EG 9.1✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image decoder when processing crafted MAP file…
- CVE-2026-25988HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image is stored in the wrong slot and never fre…
- CVE-2026-25989HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (`>` instead of `>=`) t…
- CVE-2026-26066MEDIUMCVSS 6.2EG 6.2✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted profile contain invalid IPTC data may cause an infinite loop when writing it with `IPTCTEXT`…
- CVE-2026-26283HIGHCVSS 7.5EG 7.5✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a `continue` statement in the JPEG extent binary search loop in the jpeg encoder causes an infinite lo…
- CVE-2026-26284CRITICALCVSS 9.1EG 9.1✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) file…
- CVE-2026-26983MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.10.32026-02-24
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image a…
- CVE-2026-27798HIGHCVSS 7.1EG 7.1✓ Fixed in 14.10.32026-02-26
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small dimension using the `…
- CVE-2026-27799MEDIUMCVSS 4.4EG 4.4✓ Fixed in 14.10.32026-02-26
vulnerable: 10.0.0 ... 9.1.2 (225 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occur…
- CVE-2026-28493MEDIUMCVSS 6.5EG 6.5✓ Fixed in 14.10.42026-03-10
vulnerable: 10.0.0 ... 9.1.2 (226 versions)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out…
Check whether Magick.NET-Q16-x64 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Magick.NET-Q16-x64 CVEs against the assets you own.
Start Free Scan →