peter bassill · operator
$ cve CVE-2016-3716 JSON

CVE-2016-3716 EXPLOIT

3.3
LOW · CVSS 3.0 · EPSS 11.3% (pctl 96)

Patch early

A public exploit exists.

Description

The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.

Scoring

CVSS3.3 (LOW, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS11.34% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2016-05-05
Last modified2026-06-17

Affected (10)

VendorProduct
canonicalubuntu linux
imagemagickimagemagick
redhatenterprise linux desktop
redhatenterprise linux hpc node
redhatenterprise linux hpc node eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server supplementary eus
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD