Loading
Generated remediation guidance and an executive summary. No account required.
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
Use CWE-20, Imagemagick vendor hub and Imagemagick product page to widen CVE-2016-3714 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-33908, CVE-2026-33901 and CVE-2026-40312 for nearby disclosures in the same product family.