ImageMagick
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*
- < 7.1.2-16
- < 6.9.13-41
A heap overflow vulnerability has been identified in ImageMagick versions prior to 7.1.2-16 and 6.9.13-41. This issue arises when the software processes extremely large image profiles while encoding PNG images. The vulnerability has been addressed in the mentioned patched versions.
Exploitation of this vulnerability leads to a heap buffer overwrite, which can commonly be exploited to execute arbitrary code.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.