{
  "id": "CVE-2016-3718",
  "url": "https://spydr.io/cve/CVE-2016-3718",
  "published": "2016-05-05T18:59:08.960Z",
  "modified": "2026-06-17T00:46:15.097Z",
  "score": 5.5,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
  "score_source": "NVD",
  "epss": 0.76741,
  "epss_percentile": 0.99536,
  "exploited": true,
  "kev": {
    "added": "2021-11-03",
    "due": "2022-05-03",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "ImageMagick Server-Side Request Forgery (SSRF) Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2016-3718"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "redhat",
    "imagemagick",
    "canonical",
    "oracle",
    "suse",
    "opensuse"
  ],
  "products": [
    "redhat enterprise linux desktop",
    "redhat enterprise linux eus",
    "redhat enterprise linux for ibm z systems",
    "redhat enterprise linux for ibm z systems eus",
    "redhat enterprise linux for power big endian",
    "redhat enterprise linux for power big endian eus",
    "redhat enterprise linux for power little endian",
    "redhat enterprise linux for power little endian eus",
    "redhat enterprise linux hpc node",
    "redhat enterprise linux hpc node eus",
    "redhat enterprise linux server",
    "redhat enterprise linux server aus",
    "redhat enterprise linux server from rhui",
    "redhat enterprise linux server supplementary eus",
    "redhat enterprise linux server tus",
    "redhat enterprise linux workstation",
    "imagemagick",
    "canonical ubuntu linux",
    "oracle linux",
    "oracle solaris"
  ],
  "cwes": [
    "CWE-918"
  ],
  "description": "The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 5.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLog",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2016-0726.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.debian.org/security/2016/dsa-3580",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2016/05/03/18",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.securityfocus.com/archive/1/538378/100/0/threaded",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2990-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2018/06/msg00009.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://security.gentoo.org/glsa/201611-21",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.exploit-db.com/exploits/39767/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.imagemagick.org/script/changelog.php",
      "tags": [
        "Release Notes"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3718",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3718",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
