ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 3.1 | Primary | NVD | 7.4 | 2.2 | 5.2 |
| 4.0 | Primary | cve.org | 8.2 | — | — |
| 4.0 | Secondary | NVD | 8.2 | — | — |
| 4.0 | Secondary | ENISA EUVD | 8.2 | — | — |