<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T11:30:03.437221+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09990</id>
    <title>bdu:2026-09990</title>
    <updated>2026-10-04T11:30:03.629938+00:00</updated>
    <content>bdu:2026-09990</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337182</id>
    <title>EUVD-2026-337182</title>
    <updated>2026-10-04T11:30:03.629990+00:00</updated>
    <content>EUVD-2026-337182</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56379</id>
    <title>fkie_cve-2026-56379</title>
    <updated>2026-10-04T11:30:03.630005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-56379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xpg8-7m6m-jf56</id>
    <title>GHSA-xpg8-7m6m-jf56 — ImageMagick: SVG-to-MVG Command Injection via coders/svg.c</title>
    <updated>2026-10-04T11:30:03.630035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-OpenMP-x64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-OpenMP-x86 and 9 more</p>
<p>An attacker can inject arbitrary MVG (Magick Vector Graphics) drawing commands in an SVG file that is read by the internal SVG decoder of ImageMagick. The injected MVG commands execute during rendering.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xpg8-7m6m-jf56"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11127-1</id>
    <title>openSUSE-SU-2026:11127-1 — ImageMagick-7.1.2.25-3.1 on GA media</title>
    <updated>2026-10-04T11:30:03.630087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick-7.1.2.25-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11127-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:32961</id>
    <title>RHSA-2026:32961 — Red Hat Security Advisory: ImageMagick security update</title>
    <updated>2026-10-04T11:30:03.630109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick: ImageMagick: Denial of Service due to resource policy bypass in PSD decoder ImageMagick: ImageMagick: Denial of Service due to excessive resource use in MNG coder ImageMagick: ImageMagick: Denial of Service via out-of-bounds write when processing multiple images ImageMagick: ImageMagick: Denial of Service via crafted MIFF file ImageMagick: ImageMagick: Denial of Service via crafted MSL image leading to heap-use-after-free ImageMagick: ImageMagick: Heap buffer over-write via `magick -distribute-cache` service connection ImageMagick: ImageMagick: Denial of Service via crafted DCM image with invalid dimensions ImageMagick: ImageMagick: Denial of Service via missing memory request check ImageMagick: ImageMagick: Arbitrary code execution via SVG decoder command injection</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:32961"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22620-1</id>
    <title>SUSE-SU-2026:22620-1 — Security update for ImageMagick</title>
    <updated>2026-10-04T11:30:03.630139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ImageMagick</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22620-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56379</id>
    <title>UBUNTU-CVE-2026-56379</title>
    <updated>2026-10-04T11:30:03.630159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: imagemagick, Ubuntu:Pro:16.04:LTS: imagemagick, Ubuntu:Pro:18.04:LTS: imagemagick, Ubuntu:Pro:20.04:LTS: imagemagick, Ubuntu:Pro:22.04:LTS: imagemagick, Ubuntu:Pro:24.04:LTS: imagemagick, Ubuntu:25.10: imagemagick</p>
<p>ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0484</id>
    <title>WID-SEC-W-2026-0484 — ImageMagick: Mehrere Schwachstellen</title>
    <updated>2026-10-04T11:30:03.630188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere nicht näher definierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0484"/>
  </entry>
</feed>
