Количество 5
Количество 5
CVE-2026-86424
(ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-tim ...)
CVE-2026-86424
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
CVE-2026-86424
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
CVE-2026-86424
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-tim ...
GHSA-v7f7-cw7c-4cvq
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-86424 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-tim ...) | CVSS3: 2.5 | 0% Низкий | 7 дней назад | |
CVE-2026-86424 ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations. | CVSS3: 2.5 | 0% Низкий | 9 дней назад | |
CVE-2026-86424 ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations. | CVSS3: 2.5 | 0% Низкий | 9 дней назад | |
CVE-2026-86424 ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-tim ... | CVSS3: 2.5 | 0% Низкий | 9 дней назад | |
GHSA-v7f7-cw7c-4cvq ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations. | CVSS3: 2.5 | 0% Низкий | 9 дней назад |
Уязвимостей на страницу