peter bassill · operator
$ cve CVE-2014-9846 JSON

CVE-2014-9846

9.8
CRITICAL · CVSS 3.0 · EPSS 4.9% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.85% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2017-03-20
Last modified2026-06-17

Affected (11)

VendorProduct
canonicalubuntu linux
imagemagickimagemagick
opensuseleap
opensuseopensuse
opensuse projectleap
opensuse projectsuse linux enterprise debuginfo
opensuse projectsuse linux enterprise desktop
opensuse projectsuse linux enterprise server
opensuse projectsuse linux enterprise software development kit
opensuse projectsuse linux enterprise workstation extension
susestudio onsite

References

→ the Explorer  ·  watch your stack  ·  NVD