CVE-2017-11166: ImageMagick

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

The ReadXWDImage function in coders\xwd.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted length (number of color-map entries) field in the header of an XWD file.

Affected products

Published 2017-07-10. Last modified 2026-06-17.