peter bassill · operator
$ cve CVE-2016-3717 JSON

CVE-2016-3717 EXPLOIT

5.5
MEDIUM · CVSS 3.0 · EPSS 20.4% (pctl 97)

Patch early

A public exploit exists.

Description

The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

Scoring

CVSS5.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS20.44% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2016-05-05
Last modified2026-06-17

Affected (10)

VendorProduct
canonicalubuntu linux
imagemagickimagemagick
redhatenterprise linux desktop
redhatenterprise linux hpc node
redhatenterprise linux hpc node eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server supplementary eus
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD