CVE-2018-16413: ImageMagick
High severity, CVSS 8.8. EPSS: 4.2% chance of exploitation in the next 30 days.
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the MagickCore/quantum-private.h PushShortPixel function when called from the coders/psd.c ParseImageResourceBlocks function.
Affected products
- ImageMagick ImageMagick: version 7.0.8-11 only
Published 2018-09-03. Last modified 2026-06-17.