CVE-2026-55577
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a h
CVSS
5.9
Medio
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 1 jul 2026 · Última mod.: 2 jul 2026 · CWE-754 · CWE-755 · CWE-787
0.2%EPSS · 30 días0.4%
2026-08-202026-09-17
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-252807.8 ALT1.5%
——0Memory corruption when processing escape handling flow with insufficient user buffer sizes.2dCVE-2026-240747.8 ALT5.8%
——2Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.2dCVE-2026-240737.8 ALT5.8%
——2Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.2dCVE-2026-927867.8 ALT2.7%
——1LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.2dCVE-2026-91097—50.4%
——15HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.2dCVE-2026-77411—34.9%
——10RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the declared field bytes unread, while readTable treats the operation as successful and continues parsing from the wrong offset. A malicious or compromised broker can provide an oversized longstr in a table field and desynchronize subsequent AMQP parsing, causing attacker-controlled trailing bytes to be interpreted as later fields or frames and disrupting connection integrity and availability. This issue is fixed in version 1.13.0.2d