Show filters
819 Total Results
Displaying 131-140 of 819
Sort by:
Attacker Value
Unknown

CVE-2014-8561

Disclosure Date: December 15, 2019 (last updated November 27, 2024)
imagemagick 6.8.9.6 has remote DOS via infinite loop
Attacker Value
Unknown

CVE-2019-17590

Disclosure Date: November 26, 2019 (last updated November 08, 2023)
The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and dispersing it to a victim via social engineering, enticing them to click the link. Once the user/victim clicks the "try again" button, the attacker can take over the account and perform unintended actions on the victim's behalf. NOTE: A third-party maintainer has stated that this CVE is a false report. They state that the csrf_callback function is actually a callback function to the callers own handler for output. The function called can be changed via configuration to a custom callback to handle failed validation differently. They also stated that there is no way for an attacker to change tokens to make them valid from the client side. The only thing an attack can do is to pull the token out of the javascript, but that will always be possible and has no…
Attacker Value
Unknown

CVE-2019-18853

Disclosure Date: November 11, 2019 (last updated November 27, 2024)
ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.
Attacker Value
Unknown

CVE-2019-18219

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection within both GET or POST requests, via a crafted URL or via the UpgradeMode POST parameter.
Attacker Value
Unknown

CVE-2019-18220

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated attacker to trick Sitemagic users into performing unwarranted actions.
Attacker Value
Unknown

CVE-2019-17541

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager is mishandled in coders/jpeg.c.
Attacker Value
Unknown

CVE-2019-17547

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/draw.c has a use-after-free.
Attacker Value
Unknown

CVE-2019-17540

Disclosure Date: October 14, 2019 (last updated November 08, 2023)
ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.
Attacker Value
Unknown

CVE-2019-13307

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
Attacker Value
Unknown

CVE-2019-16711

Disclosure Date: September 23, 2019 (last updated November 27, 2024)
ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.