Show filters
698 Total Results
Displaying 111-120 of 698
Sort by:
Attacker Value
Unknown
CVE-2023-26965
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.
0
Attacker Value
Unknown
CVE-2023-25434
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.
0
Attacker Value
Unknown
CVE-2013-10029
Disclosure Date: June 05, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic was found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this vulnerability is the function exitboxadmin of the file wordpress-exit-box-lite.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. Upgrading to version 1.10 is able to address this issue. The patch is named fad26701addb862c51baf85c6e3cc136aa79c309. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230671.
0
Attacker Value
Unknown
CVE-2023-29725
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
The BT21 x BTS Wallpaper app 12 for Android allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data, the attacker can force the application to load malicious image URLs and display them in the UI. As the amount of data increases, it will eventually cause the application to trigger an OOM error and crash, resulting in a persistent denial of service attack.
0
Attacker Value
Unknown
CVE-2023-29724
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this data to cause an escalation of privilege attack.
0
Attacker Value
Unknown
CVE-2023-30775
Disclosure Date: May 19, 2023 (last updated October 08, 2023)
A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.
0
Attacker Value
Unknown
CVE-2023-30774
Disclosure Date: May 19, 2023 (last updated January 09, 2024)
A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values.
0
Attacker Value
Unknown
CVE-2023-2731
Disclosure Date: May 17, 2023 (last updated October 08, 2023)
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
0
Attacker Value
Unknown
CVE-2023-30086
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.
0
Attacker Value
Unknown
CVE-2023-1916
Disclosure Date: April 10, 2023 (last updated October 08, 2023)
A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.
0