CVE-2026-105398 — ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call t…
Description
ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call to the GetVirtualPixels API. Attackers can trigger the out-of-bounds heap write through crafted input to crash the server, causing a denial of service.
CVSS v4.0 base metrics
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
High
Attack Complexity
AT
Present
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
Related threats
same CWE or vendorCVE-2026-107324 — An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a ma…
CVE-2026-107324 · 5h ago
CVE-2026-107446 — containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_b…
CVE-2026-107446 · 20h ago
CVE-2026-107224 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.
CVE-2026-107224 · 1d ago
CVE-2026-107217 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.
CVE-2026-107217 · 1d ago
CVE-2026-106574 — ImageMagick is free and open-source software used for editing and manipulating digital images.
CVE-2026-106574 · 1d ago
CVE-2026-106571 — ImageMagick is free and open-source software used for editing and manipulating digital images.
CVE-2026-106571 · 1d ago