Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56378

Опубликовано: 21 июн. 2026
Источник: nvd
CVSS3: 3.7
CVSS3: 8.2
EPSS Низкий

Описание

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия от 6.9.0-0 (включая) до 6.9.13-40 (исключая)
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия от 7.1.2-0 (включая) до 7.1.2-15 (исключая)

EPSS

Процентиль: 13%
0.00223
Низкий

3.7 Low

CVSS3

8.2 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

CVSS3: 4.8
redhat
около 1 месяца назад

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

CVSS3: 3.7
debian
около 1 месяца назад

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap ...

CVSS3: 3.7
github
около 1 месяца назад

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

CVSS3: 8.2
fstec
около 1 месяца назад

Уязвимость консольного графического редактора ImageMagick, связанная с чтением за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 13%
0.00223
Низкий

3.7 Low

CVSS3

8.2 High

CVSS3

Дефекты

CWE-125