Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown
CVE-2018-3858
Disclosure Date: July 19, 2018 (last updated November 27, 2024)
An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain the ability to execute code. A different vulnerability than CVE-2018-3857.
0
Attacker Value
Unknown
CVE-2018-3857
Disclosure Date: July 19, 2018 (last updated November 27, 2024)
An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution. A different vulnerability than CVE-2018-3858.
0
Attacker Value
Unknown
CVE-2018-3870
Disclosure Date: July 19, 2018 (last updated November 27, 2024)
An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution. A different vulnerability than CVE-2018-3871.
0
Attacker Value
Unknown
CVE-2018-3859
Disclosure Date: July 19, 2018 (last updated November 27, 2024)
An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution. A different vulnerability than CVE-2018-3860.
0
Attacker Value
Unknown
CVE-2018-3871
Disclosure Date: July 19, 2018 (last updated November 27, 2024)
An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution. A different vulnerability than CVE-2018-3870.
0
Attacker Value
Unknown
CVE-2018-3860
Disclosure Date: July 19, 2018 (last updated November 27, 2024)
An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain the ability to execute code. A different vulnerability than CVE-2018-3859.
0
Attacker Value
Unknown
CVE-2017-1000507
Disclosure Date: February 09, 2018 (last updated November 26, 2024)
Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code.
0
Attacker Value
Unknown
CVE-2017-8298
Disclosure Date: April 27, 2017 (last updated November 26, 2024)
cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users.
0
Attacker Value
Unknown
CVE-2014-1683
Disclosure Date: January 29, 2014 (last updated October 05, 2023)
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.
0
Attacker Value
Unknown
CVE-2009-2116
Disclosure Date: June 18, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.
0