CVE-2014-9852 is a critical vulnerability in ImageMagick, affecting imagemagick, opensuse, and suse products. It involves a use-after-free error in distribute-cache.c, allowing remote attackers to achieve high impact on confidentiality, integrity, and availability with low attack complexity and no user interaction. While rated with a CVSS score of 9.8 and a FAUCET Risk Score of 93/100, there is no evidence of active exploitation, public exploit code, or KEV catalog inclusion. Despite its age, the vulnerability still garners significant community discussion, with 10 mentions, though no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.9.4-0CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:12:sp1:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.