NuGet Package Vulnerabilities
Vulnerabilities associated with Magick.NET-Q16-OpenMP-x86.
Packages
Clear package- Microsoft.ChakraCore247 vulnerabilities
- Magick.NET-Q16-AnyCPU163 vulnerabilities
- Magick.NET-Q16-HDRI-AnyCPU163 vulnerabilities
- Magick.NET-Q8-AnyCPU163 vulnerabilities
- Magick.NET-Q16-HDRI-x86162 vulnerabilities
- Magick.NET-Q16-x86161 vulnerabilities
- Magick.NET-Q8-x86161 vulnerabilities
- Magick.NET-Q16-HDRI-OpenMP-arm64159 vulnerabilities
- Magick.NET-Q16-HDRI-x64159 vulnerabilities
- Magick.NET-Q16-OpenMP-arm64159 vulnerabilities
- Magick.NET-Q16-OpenMP-x64159 vulnerabilities
- Magick.NET-Q16-arm64159 vulnerabilities
- Magick.NET-Q16-HDRI-arm64158 vulnerabilities
- Magick.NET-Q8-OpenMP-arm64158 vulnerabilities
- Magick.NET-Q8-arm64158 vulnerabilities
- Magick.NET-Q8-OpenMP-x64155 vulnerabilities
- Magick.NET-Q16-x64154 vulnerabilities
- Magick.NET-Q8-x64152 vulnerabilities
- Magick.NET-Q16-HDRI-OpenMP-x6495 vulnerabilities
- Magick.NET-Q16-OpenMP-x8667 vulnerabilities
- DotNetNuke.Core36 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-x6427 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-x8626 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-arm25 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.linux-x6424 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-56368MEDIUM | ImageMagick - Memory Leak in Raw Pixel Data CodersImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service. CWE-401Jun 24, 2026 | CVSS6.3v4.0 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
ImageMagick: META reader memory leak in the APP1JPEG input pathImageMagick contains a memory leak in the META reader when processing the `APP1JPEG` input path. CWE-401Mar 26, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick has possible memory leak in ASHLAR coder when action failsThe ASHLAR coder leaks a temporary image when an action fails and that could result to an out of memory. CWE-401Mar 26, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-33536MEDIUM | ImageMagick has an Out-of-bounds Write via InterpretImageFilenameImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, due to an incorrect return value on certain platforms a pointer is incremented past the end of a buffer that is on the stack and that could result in an out of bounds write. Versions 7.1.2-18 and 6.9.13-43 patch the issue. | CVSS5.1v3.1 | EPSS0.128% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33535MEDIUM | ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interactionImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue. CWE-787Mar 26, 2026 | CVSS4.0v3.1 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32636MEDIUM | ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crashImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue. CWE-787Mar 18, 2026 | CVSS5.3v3.1 | EPSS0.475% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-31853MEDIUM | ImageMagick has a heap buffer over-write on 32-bit systems in SFW decoderImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit systems can cause a crash in the SFW decoder when processing extremely large images. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. CWE-122Mar 11, 2026 | CVSS5.7v3.1 | EPSS0.093% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30937MEDIUM | ImageMagick has a heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculationImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. | CVSS6.8v3.1 | EPSS0.099% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30936MEDIUM | ImageMagick has a heap Buffer Overflow in WaveletDenoiseImageImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a crafted image could cause an out of bounds heap write inside the WaveletDenoiseImage method. When processing a crafted image with the -wavelet-denoise operation an out of bounds write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. CWE-122Mar 9, 2026 | CVSS5.5v3.1 | EPSS0.106% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30935MEDIUM | ImageMagick has a heap Buffer Over-Read in BilateralBlurImageImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, BilateralBlurImage contains a heap buffer over-read caused by an incorrect conversion. When processing a crafted image with the -bilateral-blur operation an out of bounds read can occur. This vulnerability is fixed in 7.1.2-16. | CVSS4.4v3.1 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30931MEDIUM | ImageMagick has a heap-based buffer overflow in UHDR encoderImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, a heap-based buffer overflow in the UHDR encoder can happen due to truncation of a value and it would allow an out of bounds write. This vulnerability is fixed in 7.1.2-16. CWE-122Mar 9, 2026 | CVSS6.8v3.1 | EPSS0.108% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30929HIGH | ImageMagick has a stack buffer overflow in MagnifyImageImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MagnifyImage uses a fixed-size stack buffer. When using a specific image it is possible to overflow this buffer and corrupt the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. | CVSS7.7v3.1 | EPSS0.107% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30883MEDIUM | ImageMagick has a Heap Overflow when writing extremely large image profile in the PNG encoderImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an extremely large image profile could result in a heap overflow when encoding a PNG image. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. CWE-119Mar 9, 2026 | CVSS5.7v3.1 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28693HIGH | ImageMagick has an integer overflow in DIB coder can result in out of bounds read or writeImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. | CVSS8.1v3.1 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28692MEDIUM | ImageMagick has a heap buffer over-read via 32-bit integer overflow in MAT decoderImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MAT decoder uses 32-bit arithmetic due to incorrect parenthesization resulting in a heap over-read. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. CWE-125Mar 9, 2026 | CVSS4.8v3.1 | EPSS0.258% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28691HIGH | ImageMagick has an uninitialized pointer dereference in JBIG decoderImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. | CVSS7.5v3.1 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28690MEDIUM | ImageMagick has a stack write buffer overflow in MNG encoderImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encoder. There is a bounds checks missing that could corrupting the stack with attacker-controlled data. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. CWE-121Mar 9, 2026 | CVSS6.9v3.1 | EPSS0.096% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28689MEDIUM | ImageMagick has a Path Policy TOCTOU symlink race bypassImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, domain="path" authorization is checked before final file open/use. A symlink swap between check-time and use-time bypasses policy-denied read/write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. | CVSS6.3v3.1 | EPSS0.108% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28688MEDIUM | ImageMagick has a heap use-after-free in the MSL encoderImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-after-free vulnerability exists in the MSL encoder, where a cloned image is destroyed twice. The MSL coder does not support writing MSL so the write capability has been removed. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. CWE-416Mar 9, 2026 | CVSS4.0v3.1 | EPSS0.193% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28687MEDIUM | ImageMagick has a Heap Use-After-Free in ImageMagick MSL decoderImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. CWE-416Mar 9, 2026 | CVSS5.3v3.1 | EPSS0.243% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28686MEDIUM | ImageMagick has a write heap-buffer-overflow in PCL encoder via undersized output bufferImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, A heap-buffer-overflow vulnerability exists in the PCL encode due to an undersized output buffer allocation. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. | CVSS6.8v3.1 | EPSS0.113% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28494HIGH | ImageMagick affected by stack corruption through long morphology kernel names or arraysImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. CWE-121Mar 9, 2026 | CVSS7.1v3.1 | EPSS0.108% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28493MEDIUM | ImageMagick has a Integer Overflow leading to out of bounds write in SIXEL decoderImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image. This vulnerability is fixed in 7.1.2-16. CWE-190Mar 9, 2026 | CVSS6.5v3.1 | EPSS0.194% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27799MEDIUM | ImageMagick has a heap Buffer Over-read in its DJVU image format handlerImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row size) for pixel buffer allocation. The stride calculation overflows a 32-bit signed integer, resulting in an out-of-bounds memory reads. Versions 7.1.2-15 and 6.9.13-40 contain a patch. | CVSS4.0v3.1 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27798MEDIUM | ImageMagick: Heap Buffer Over-read in WaveletDenoise when processing small imagesImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small dimension using the `-wavelet-denoise` operator. Versions 7.1.2-15 and 6.9.13-40 contain a patch. | CVSS4.0v3.1 | EPSS0.137% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |