CVE-2016-3714

CVE Published 2016-05-05
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) imagemagick, debian, suse, canonical, opensuse
Related Product(s) imagemagick, ubuntu_linux, debian_linux, opensuse, leap, suse_linux_enterprise_server
Exploitation Reported (CISA KEV) 2024-09-09
CVSS 3 Base Score 8.4 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References