Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2020-29244

Disclosure Date: December 28, 2020 (last updated February 22, 2025)
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.
Attacker Value
Unknown

CVE-2020-15272

Disclosure Date: October 26, 2020 (last updated February 22, 2025)
In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has been patched in version 1.0.1. If you don't use the `tag` input you are most likely safe. The `GITHUB_REF` environment variable is protected by the GitHub Actions environment so attacks from there should be impossible. If you must use the `tag` input and cannot upgrade to `> 1.0.0` make sure that the value is not controlled by another Action.
Attacker Value
Unknown

CVE-2017-18546

Disclosure Date: August 16, 2019 (last updated November 27, 2024)
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
0
Attacker Value
Unknown

CVE-2017-9426

Disclosure Date: February 26, 2018 (last updated November 26, 2024)
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.
0
Attacker Value
Unknown

CVE-2017-9425

Disclosure Date: February 26, 2018 (last updated November 26, 2024)
The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action.
0
Attacker Value
Unknown

CVE-2017-11551

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file.
0
Attacker Value
Unknown

CVE-2017-11550

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.
0