<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:40:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-10857</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10857</link>
      <description>bdu:2025-10857</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10857</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</link>
      <description>certfr-2025-avi-0969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</guid>
    </item>
    <item>
      <title>EUVD-2026-249654</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-249654</link>
      <description>EUVD-2026-249654</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-249654</guid>
    </item>
    <item>
      <title>fkie_cve-2025-55004</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55004</link>
      <description>&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-55004</guid>
    </item>
    <item>
      <title>GHSA-cjc8-g9w8-chfw — imagemagick: heap-buffer overflow read in MNG magnification with alpha</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cjc8-g9w8-chfw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-OpenMP-x64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-arm64 and 8 more&lt;/p&gt;
&lt;p&gt;## **Vulnerability Details**&lt;/p&gt;
&lt;p&gt;When performing image magnification in `ReadOneMNGIMage` (in `coders/png.c`), there is an issue around the handling of images with separate alpha channels.&lt;/p&gt;
&lt;p&gt;When loading an image with a color type that implies a separate alpha channel (ie. `jng_color_type &amp;gt;= 12`), we will load the alpha pixels in this loop:&lt;/p&gt;
&lt;p&gt;```c
     if (logging != MagickFalse)
        (void) LogMagickEvent(CoderEvent,GetMagickModule(),
          &amp;#34;    Reading alpha from alpha_blob.&amp;#34;);
      jng_image=ReadImage(alpha_image_info,exception);&lt;/p&gt;
&lt;p&gt;if (jng_image != (Image *) NULL)
        for (y=0; y &amp;lt; (ssize_t) image-&amp;gt;rows; y++)
        {
          s=GetVirtualPixels(jng_image,0,y,image-&amp;gt;columns,1,exception);
          q=GetAuthenticPixels(image,0,y,image-&amp;gt;columns,1,exception); // [0]
          if ((s == (const Quantum *)  NULL) || (q == (Quantum *) NULL))
            break;&lt;/p&gt;
&lt;p&gt;if (image-&amp;gt;alpha_trait != UndefinedPixelTrait)
            for (x=(ssize_t) image-&amp;gt;columns; x != 0; x--)
            {
              SetPixelAlpha(image,GetPixelRed(jng_image,s),q);
              q+=(ptrdiff_t) GetPixelChannels(image);
              s+=(ptrdiff_t) GetPixelChannels(jng_image);
            }&lt;/p&gt;
&lt;p&gt;else
            for (x=(ssize_t) image-&amp;gt;columns; x != 0; x--)
            {
              Quantum
                alpha;&lt;/p&gt;
&lt;p&gt;alpha=GetPixelRed(jng_image,s);
              SetPixelAlpha(image,alpha,q);
              if (alpha != OpaqueAlpha)
                image-&amp;gt;alpha_trai…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-OpenMP-x64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-arm64 and 8 more&lt;/p&gt;
&lt;p&gt;## **Vulnerability Details**&lt;/p&gt;
&lt;p&gt;When performing image magnification in `ReadOneMNGIMage` (in `coders/png.c`), there is an issue around the handling of images with separate alpha channels.&lt;/p&gt;
&lt;p&gt;When loading an image with a color type that implies a separate alpha channel (ie. `jng_color_type &amp;gt;= 12`), we will load the alpha pixels in this loop:&lt;/p&gt;
&lt;p&gt;```c
     if (logging != MagickFalse)
        (void) LogMagickEvent(CoderEvent,GetMagickModule(),
          &amp;#34;    Reading alpha from alpha_blob.&amp;#34;);
      jng_image=ReadImage(alpha_image_info,exception);&lt;/p&gt;
&lt;p&gt;if (jng_image != (Image *) NULL)
        for (y=0; y &amp;lt; (ssize_t) image-&amp;gt;rows; y++)
        {
          s=GetVirtualPixels(jng_image,0,y,image-&amp;gt;columns,1,exception);
          q=GetAuthenticPixels(image,0,y,image-&amp;gt;columns,1,exception); // [0]
          if ((s == (const Quantum *)  NULL) || (q == (Quantum *) NULL))
            break;&lt;/p&gt;
&lt;p&gt;if (image-&amp;gt;alpha_trait != UndefinedPixelTrait)
            for (x=(ssize_t) image-&amp;gt;columns; x != 0; x--)
            {
              SetPixelAlpha(image,GetPixelRed(jng_image,s),q);
              q+=(ptrdiff_t) GetPixelChannels(image);
              s+=(ptrdiff_t) GetPixelChannels(jng_image);
            }&lt;/p&gt;
&lt;p&gt;else
            for (x=(ssize_t) image-&amp;gt;columns; x != 0; x--)
            {
              Quantum
                alpha;&lt;/p&gt;
&lt;p&gt;alpha=GetPixelRed(jng_image,s);
              SetPixelAlpha(image,alpha,q);
              if (alpha != OpaqueAlpha)
                image-&amp;gt;alpha_trai…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cjc8-g9w8-chfw</guid>
    </item>
    <item>
      <title>OESA-2025-2193 — ImageMagick security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2193</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: ImageMagick&lt;/p&gt;
&lt;p&gt;Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.(CVE-2025-55004)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB colorspaces, the logmap construction fails to handle cases where the reference-black or reference-white value is larger than 1024. This leads to corrupting memory beyond the end of the allocated logmap buffer. This issue has been patched in version 7.1.2-1.(CVE-2025-55005)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: ImageMagick&lt;/p&gt;
&lt;p&gt;Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.(CVE-2025-55004)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB colorspaces, the logmap construction fails to handle cases where the reference-black or reference-white value is larger than 1024. This leads to corrupting memory beyond the end of the allocated logmap buffer. This issue has been patched in version 7.1.2-1.(CVE-2025-55005)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2193</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03151-1 — Security update for ImageMagick</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03151-1</link>
      <description>&lt;p&gt;Security update for ImageMagick&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ImageMagick&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03151-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-55004</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55004</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: imagemagick&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: imagemagick&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55004</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1813 — ImageMagick: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1813</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, beliebigen Code auszuführen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, beliebigen Code auszuführen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1813</guid>
    </item>
  </channel>
</rss>
