CVE-2016-10047: ImageMagick

Medium severity, CVSS 5.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Memory leak in the NewXMLTree function in magick/xml-tree.c in ImageMagick before 6.9.4-7 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML file.

Affected products

Published 2017-03-23. Last modified 2026-06-17.