CVE-2006-2440
Status: ModifiedHigh (7.5)—
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.86%
- Percentile among all scored CVEs: 86
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595
- http://secunia.com/advisories/21719
- http://secunia.com/advisories/24186
- http://secunia.com/advisories/24284
- http://www.debian.org/security/2006/dsa-1168
- http://www.redhat.com/support/errata/RHSA-2007-0015.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595
- http://secunia.com/advisories/21719
- http://secunia.com/advisories/24186
- http://secunia.com/advisories/24284
- http://www.debian.org/security/2006/dsa-1168
- http://www.redhat.com/support/errata/RHSA-2007-0015.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481
Raw JSON (NVD)
Show
{
"id": "CVE-2006-2440",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-05-18T10:02:00.000",
"references": [
{
"url": "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/21719",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24186",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24284",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2006/dsa-1168",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2007-0015.html",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481",
"source": "cve@mitre.org"
},
{
"url": "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/21719",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/24186",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/24284",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2006/dsa-1168",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2007-0015.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function."
}
],
"lastModified": "2026-06-16T22:25:00.880",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:6.0.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F91C63C5-765B-4511-B6CF-CA09433DE051"
},
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:6.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDA9ACBD-6065-4340-B987-560BE5A54FE1"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Red Hat is aware of this issue and is tracking it via the following bug:\nhttps://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=192278\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:\nhttp://www.redhat.com/security/updates/classification/\n\nThis issue does not affect Red Hat Enterprise Linux 2.1 or 3.\n",
"lastModified": "2006-09-19T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}