Show filters
819 Total Results
Displaying 131-140 of 819
Sort by:
Attacker Value
Unknown
CVE-2014-8561
Disclosure Date: December 15, 2019 (last updated November 27, 2024)
imagemagick 6.8.9.6 has remote DOS via infinite loop
0
Attacker Value
Unknown
CVE-2019-17590
Disclosure Date: November 26, 2019 (last updated November 08, 2023)
The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and dispersing it to a victim via social engineering, enticing them to click the link. Once the user/victim clicks the "try again" button, the attacker can take over the account and perform unintended actions on the victim's behalf. NOTE: A third-party maintainer has stated that this CVE is a false report. They state that the csrf_callback function is actually a callback function to the callers own handler for output. The function called can be changed via configuration to a custom callback to handle failed validation differently. They also stated that there is no way for an attacker to change tokens to make them valid from the client side. The only thing an attack can do is to pull the token out of the javascript, but that will always be possible and has no…
0
Attacker Value
Unknown
CVE-2019-18853
Disclosure Date: November 11, 2019 (last updated November 27, 2024)
ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.
0
Attacker Value
Unknown
CVE-2019-18219
Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection within both GET or POST requests, via a crafted URL or via the UpgradeMode POST parameter.
0
Attacker Value
Unknown
CVE-2019-18220
Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated attacker to trick Sitemagic users into performing unwarranted actions.
0
Attacker Value
Unknown
CVE-2019-17541
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager is mishandled in coders/jpeg.c.
0
Attacker Value
Unknown
CVE-2019-17547
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/draw.c has a use-after-free.
0
Attacker Value
Unknown
CVE-2019-17540
Disclosure Date: October 14, 2019 (last updated November 08, 2023)
ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.
0
Attacker Value
Unknown
CVE-2019-13307
Disclosure Date: October 10, 2019 (last updated November 27, 2024)
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
0
Attacker Value
Unknown
CVE-2019-16711
Disclosure Date: September 23, 2019 (last updated November 27, 2024)
ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
0