Record summary

CVE-2026-33535 has a selected CVSS score of 4.0 (medium).

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 27, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 19
ProductSourceVersion rangeStatus
CVE List< 7.1.2-18affected
< 6.9.13-43affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected

Magick.NET-Q16-HDRI-OpenMP-arm64

Browse NuGet / Magick.NET-Q16-HDRI-OpenMP-arm64
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected
GitHub AdvisoryBefore 14.11.1 · Fixed in 14.11.1affected

References

3