ImageMagick 7.1

Status MaintainedSupport 2021-06 – —Latest 7.1.2-21Vulnerabilities 119← All ImageMagick versions
Critical 9.8
2023-05-30< 7.1.1-11

ImageMagick: RCE (shell command injection) vulnerability in OpenBlob with --enable-pipes configured

High 8.8
2025-08-13< 7.1.2-1

ImageMagick: integer overflows in MNG magnification

High 8.6
2026-02-24< 7.1.2-15

ImageMagick's policy bypass through path traversal allows reading restricted content despite secured policy

High 8.2
2026-02-24< 7.1.2-15

ImageMagick has heap-buffer-overflow via signed integer overflow in `WriteUHDRImage` when writing UHDR images with large dimensions

High 8.1
2026-03-09< 7.1.2-16

ImageMagick has an integer overflow in DIB coder can result in out of bounds read or write

High 8.1
2026-01-20< 7.1.2-13

Heap buffer overflow with attacker-controlled data in XBM parser

High 7.8
2021-11-19= 7.1.0-14

ImageMagick: heap-use-after-free in at dcm.c RelinquishDCMMemory

High 7.8
2022-05-08= 7.1.0-27

ImageMagick: heap-buffer-overflow in PushLongPixel() of quantum-private.h

High 7.8
2022-06-16< 7.1.0-30

ImageMagick: load of misaligned address at MagickCore/property.c

High 7.8
2022-06-16< 7.1.0-29

ImageMagick: outside the range of representable values of type 'unsigned long' at coders/pcl.c

High 7.8
2022-06-16< 7.1.0-28

ImageMagick: outside the range of representable values of type 'unsigned char' at coders/psd.c

High 7.8
2023-05-30< 7.1.1-11

ImageMagick: Shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding

High 7.7
2026-03-09< 7.1.2-16

ImageMagick has a stack buffer overflow in MagnifyImage

High 7.6
2025-08-13< 7.1.2-1

ImageMagick: heap-buffer overflow read in MNG magnification with alpha

High 7.5
2026-04-13< 7.1.2-19

ImageMagick is vulnerable to Stack Overflow in DestroyXMLTree()

High 7.5
2026-04-13< 7.1.2-19

ImageMagick has a Heap Buffer Overflow via MVG decoder

High 7.5
2026-03-09< 7.1.2-16

ImageMagick has an uninitialized pointer dereference in JBIG decoder

High 7.5
2026-02-24< 7.1.2-15

ImageMagick has integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoder

High 7.5
2026-02-24< 7.1.2-15

Memory allocation with excessive without limits in the internal SVG decoder

High 7.5
2026-02-24< 7.1.2-15

ImageMagick: Infinite loop vulnerability when parsing a PCD file

High 7.5
2026-02-24< 7.1.2-15

ImageMagick has Possible Heap Information Disclosure in PSD ZIP Decompression

High 7.5
2025-12-10< 7.1.2-10

ImageMagick is vulnerable to an Integer Overflow in TIM decoder leading to out of bounds read (32-bit only)

High 7.5
2025-08-26< 7.1.2-2

ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow

High 7.5
2025-08-26< 7.1.2-2

ImageMagick Format String Bug in InterpretImageFilename leads to arbitrary code execution

High 7.5
2025-07-14< 7.1.2-0

ImageMagick has XMP profile write that triggers hang due to unbounded loop

High 7.5
2023-08-22< 7.1.0-4

ImageMagick: Division by zero in ReadEnhMetaFile lead to DoS

High 7.4
2026-02-24< 7.1.2-15

ImageMagick has MSL attribute stack buffer overflow that leads to out of bounds write.

High 7.4
2026-02-24< 7.1.2-15

ImageMagick has stack buffer overflow in FTXT reader via oversized integer field

High 7.4
2025-07-14< 7.1.2-0

ImageMagick has Stack Buffer Overflow in image.c

High 7.1
2026-03-09< 7.1.2-16

ImageMagick affected by stack corruption through long morphology kernel names or arrays

High 7.1
2022-04-29< 7.1.0-28

ImageMagick: heap-use-after-free in RelinquishDCMInfo of dcm.c

High 7.1
2022-08-29< 7.1.0-20

ImageMagick: Heap buffer overread in GetPixelAlpha() declared in MagickCore/pixel-accessor.h

High 7.0
2024-07-29< 7.1.1-36

Arbitrary Code Execution in `AppImage` version `ImageMagick`

Medium 6.9
2026-03-09< 7.1.2-16

ImageMagick has a stack write buffer overflow in MNG encoder

Medium 6.8
2026-03-09< 7.1.2-16

ImageMagick has a heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation

Medium 6.8
2026-03-09< 7.1.2-16

ImageMagick has a heap-based buffer overflow in UHDR encoder

Medium 6.8
2026-03-09< 7.1.2-16

ImageMagick has a write heap-buffer-overflow in PCL encoder via undersized output buffer

Medium 6.7
2026-03-12< 7.1.2-16

ImageMagick has a possible stack buffer overflow in sixel encoder

Medium 6.5
2026-03-09< 7.1.2-16

ImageMagick has a Integer Overflow leading to out of bounds write in SIXEL decoder

Medium 6.5
2026-02-24< 7.1.2-15

ImageMagick has heap overflow in pcd decoder that leads to out of bounds read.

Medium 6.5
2026-02-24< 7.1.2-15

ImageMagick Has Heap Out-of-Bounds Read in DCM Decoder (ReadDCMImage)

Medium 6.5
2026-02-24< 7.1.2-15

Imagemagick Has Global Buffer Overflow (OOB Read) via Negative Pixel Index in UIL and XPM Writer

Medium 6.5
2026-02-24< 7.1.2-15

ImageMagick has heap overflow in sun decoder on 32-bit systems that can result in out of bounds write

Medium 6.5
2026-01-22< 7.1.2-13

ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load

Medium 6.5
2026-01-20< 7.1.2-13

ImageMagick vulnerable to Release of Invalid Pointer in BilateralBlur when memory allocation fails

Medium 6.5
2023-02-06= 7.1.0-49

ImageMagick: Denial of Service when it parses a PNG image

Medium 6.5
2023-02-06= 7.1.0-49

ImageMagick: vulnerable to Information Disclosure when it parses a PNG image

Medium 6.3
2026-03-09< 7.1.2-16

ImageMagick has a Path Policy TOCTOU symlink race bypass

Medium 6.2
2026-04-13< 7.1.2-19

ImageMagick: Off-by-One in MSL decoder could result in crash

Medium 6.2
2026-04-13< 7.1.2-19

ImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encoders

Medium 6.2
2026-02-24< 7.1.2-15

ImageMagick has possible infinite loop in JPEG encoder when using `jpeg:extent`

Medium 6.2
2026-02-24< 7.1.2-15

ImageMagick has infinite loop when writing IPTCTEXT leads to denial of service via crafted profile

Medium 6.2
2026-02-24< 7.1.2-15

ImageMagick's MSL: Stack overflow in ProcessMSLScript

Medium 6.2
2023-10-04< 7.1.1-19

Imagemagick: heap-buffer-overflow in coders/tiff.c

Medium 6.2
2023-11-19< 7.1.1-43

Imagemagick: heap use-after-free in coders/bmp.c

Medium 6.1
2025-08-13< 7.1.2-1

ImageMagick Undefined Behavior (function-type-mismatch) in CloneSplayTree

Medium 5.9
2026-04-13< 6.9.13-44

ImageMagick has a Heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds

Medium 5.9
2026-02-24< 7.1.2-15

ImageMagick's Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to stdin/stdout access

Medium 5.9
2025-10-17< 7.1.2-7

ImageMagick vulnerable to denial of service via integer overflow in BMP decoder on 32-bit systems

Medium 5.7
2026-03-11< 7.1.2-16

ImageMagick has a heap buffer over-write on 32-bit systems in SFW decoder

Medium 5.7
2026-03-09< 7.1.2-16

ImageMagick has a Heap Overflow when writing extremely large image profile in the PNG encoder

Medium 5.7
2026-02-24< 7.1.2-15

ImageMagick vulnerable to Code injection via PostScript header in ps coders

Medium 5.5
2026-04-13< 7.1.2-19

ImageMagick: Heap buffer overflow when encoding JXL image with a 16-bit float

Medium 5.5
2026-04-13< 7.1.2-19

ImageMagick: Heap out-of-bounds write in JP2 encoder

Medium 5.5
2026-04-13< 7.1.2-19

ImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing values

Medium 5.5
2026-04-13< 7.1.2-19

ImageMagick has an Out-of-Bounds read via -sample operation

Medium 5.5
2026-04-13< 7.1.2-19

ImageMagick: Stack Overflow via Recursive FX Expression Parsing

Medium 5.5
2026-03-09< 7.1.2-16

ImageMagick has a heap Buffer Overflow in WaveletDenoiseImage

Medium 5.5
2026-01-20< 7.1.2-13

ImageMagick's MSL: Stack overflow via infinite recursion in ProcessMSLScript

Medium 5.5
2025-08-13< 7.1.2-1

ImageMagick: heap-buffer overflow in log colorspace handling

Medium 5.5
2022-03-23< 7.1.0-19

imagemagick: remote DoS in MagicCore/draw.c via crafted SVG file

Medium 5.5
2022-08-29< 7.1.0-29

ImageMagick: heap-buffer-overflow in PushShortPixel of quantum-private.h

Medium 5.5
2022-09-19< 7.1.0-47

ImageMagick: heap buffer overflow while processing a malformed TIFF file

Medium 5.5
2022-08-09< 7.1.0-30

ImageMagick: Assertion Failure could lead to DoS due to attempted writing of NULL image list

Medium 5.5
2023-06-16< 7.1.1-10

ImageMagick: heap-based buffer overflow in ReadTIM2ImageData() function in coders/tim2.c

Medium 5.5
2023-06-16< 7.1.1-10

ImageMagick: heap use-after-free issue in ReplaceXmpValue() function in MagickCore/profile.c.

Medium 5.5
2023-06-16< 7.1.1-10

ImageMagick: stack overflow in coders/tiff.c while parsing malicious tiff file

Medium 5.5
2023-06-06< 7.1.1-9

ImageMagick: heap overflow vulnerability

Medium 5.5
2023-04-12= 7.1.1-4

ImageMagick: heap-based buffer overflow in ImportMultiSpectralQuantum() in MagickCore/quantum-import.c

Medium 5.5
2023-03-23< 7.1.1-0

ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage DoS

Medium 5.5
2023-05-30< 7.1.1-11

ImageMagick: Undefined behaviors of casting double to size_t in svg, mvg and other coders

Medium 5.3
2026-04-13< 7.1.2-19

ImageMagick: Heap BufferOverflow write of single zero byte when parsing XML

Medium 5.3
2026-03-18< 7.1.2-17

ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crash

Medium 5.3
2026-03-09< 7.1.2-16

ImageMagick has a Heap Use-After-Free in ImageMagick MSL decoder

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick: Invalid MSL <map> can result in a use after free

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick's MSL image stack index not refreshed, leading to leaked images.

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick has heap buffer over-read in MAP image decoder

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick has a heap buffer overflow in YUV 4:2:2 decoder

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick has Use After Free in MSLStartElement in "coders/msl.c"

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick SIXEL Decoder Has Signed Integer Overflow, Leading to Memory Corruption

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick has Memory Leak in coders/ashlar.c

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick has Division-by-Zero in YUV sampling factor validation, which leads to crash

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick has NULL Pointer Dereference in ClonePixelCacheRepository via crafted image

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick has memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-return paths

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick has NULL pointer dereference in ReadSFWImage after DestroyImageInfo (sfw.c)

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick has memory leak in msl encoder

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick: Possible memory leak in ASHLAR encoder

Medium 5.3
2026-02-24< 7.1.2-15

ImageMagick: Converting multi-layer nested MVG to SVG can cause DoS

Medium 5.3
2025-12-30< 7.1.2-12

ImageMagick converting a malicious MVG file to SVG caused an integer overflow.

Medium 5.3
2025-12-30< 7.1.2-12

Magick's failure to limit the depth of SVG file reads caused a DoS attack.

Medium 5.1
2026-04-13< 7.1.2-19

ImageMagick: Integer overflow in despeckle operation causes heap buffer overflow on 32-bit builds

Medium 5.1
2026-03-26< 7.1.2-18

ImageMagick has an Out-of-bounds Write via InterpretImageFilename

Medium 5.1
2026-02-24< 7.1.2-15

ImageMagick: Out of bounds read in multiple coders read raw pixel data

Medium 4.9
2025-12-02< 7.1.2-9

ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family

Medium 4.8
2026-03-09< 7.1.2-16

ImageMagick has a heap buffer over-read via 32-bit integer overflow in MAT decoder

Medium 4.7
2025-10-27< 7.1.2-8

ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)

Medium 4.4
2026-03-09< 7.1.2-16

ImageMagick has a heap Buffer Over-Read in BilateralBlurImage

Medium 4.4
2021-09-13< 7.1.0-7

Issue when Configuring the ImageMagick Security Policy

Medium 4.0
2026-03-26< 7.1.2-18

ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction

Medium 4.0
2026-03-09< 7.1.2-16

ImageMagick has a heap use-after-free in the MSL encoder

Medium 4.0
2026-02-25< 7.1.2-15

ImageMagick has a heap Buffer Over-read in its DJVU image format handler

Medium 4.0
2026-02-25< 7.1.2-15

ImageMagick: Heap Buffer Over-read in WaveletDenoise when processing small images

Medium 4.0
2025-12-30< 7.1.2-12

Magick's failure to limit MVG mutual references forming a loop

Low 3.8
2025-09-05< 7.1.2-3

ImageMagick BlobStream Forward-Seek Under-Allocation

Low 3.7
2025-08-26< 7.1.2-2

ImageMagick affected by divide-by-zero in ThumbnailImage via montage -geometry ":" leads to crash

Low 3.7
2025-07-14< 7.1.2-0

ImageMagick has Heap Buffer Overflow in InterpretImageFilename

Low 3.3
2025-12-18< 7.1.1-14

ImageMagick vulnerable to heap-buffer-overflow

Low 2.9
2025-04-23< 7.1.1-44

ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing

Low 2.9
2025-04-23< 7.1.1-44

ImageMagick: Incorrect Handling of Image Depth in MIFF Processing in ImageMagick