Show filters
113 Total Results
Displaying 101-110 of 113
Sort by:
Attacker Value
Unknown

CVE-2009-1405

Disclosure Date: April 24, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set_lng parameter.
0
Attacker Value
Unknown

CVE-2009-0792

Disclosure Date: April 14, 2009 (last updated November 08, 2023)
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
0
Attacker Value
Unknown

CVE-2009-0793

Disclosure Date: April 09, 2009 (last updated October 04, 2023)
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
0
Attacker Value
Unknown

CVE-2009-0583

Disclosure Date: March 23, 2009 (last updated October 04, 2023)
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
0
Attacker Value
Unknown

CVE-2009-0279

Disclosure Date: January 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2008-5317

Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
0
Attacker Value
Unknown

CVE-2008-5316

Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.
0
Attacker Value
Unknown

CVE-2008-2913

Disclosure Date: June 30, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the currentpath parameter, in conjunction with certain ... (triple dot) and ..... sequences in the currentfile parameter, to index.php.
0
Attacker Value
Unknown

CVE-2008-0254

Disclosure Date: January 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.
0
Attacker Value
Unknown

CVE-2007-2822

Disclosure Date: May 22, 2007 (last updated October 04, 2023)
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.
0