CVE-2016-6520: ImageMagick

Critical severity, CVSS 9.1. EPSS: 4.2% chance of exploitation in the next 30 days.

Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.

Affected products

  • ImageMagick ImageMagick: from 7.0.0-0, before 7.0.2-7 (fixed in 7.0.2-7)

Published 2016-12-13. Last modified 2026-06-17.