Show filters
700 Total Results
Displaying 21-30 of 700
Sort by:
Attacker Value
Unknown

CVE-2013-6365

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
Attacker Value
Unknown

CVE-2017-5331

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
Attacker Value
Unknown

CVE-2017-5332

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
Attacker Value
Unknown

CVE-2017-5333

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
Attacker Value
Unknown

CVE-2014-5220

Disclosure Date: June 08, 2018 (last updated November 08, 2023)
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
0
Attacker Value
Unknown

CVE-2016-5314

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.
0
Attacker Value
Unknown

CVE-2016-1254

Disclosure Date: December 05, 2017 (last updated November 08, 2023)
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
0
Attacker Value
Unknown

CVE-2014-3462

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
Attacker Value
Unknown

CVE-2015-5203

Disclosure Date: August 02, 2017 (last updated November 08, 2023)
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
0
Attacker Value
Unknown

CVE-2015-5221

Disclosure Date: July 25, 2017 (last updated November 08, 2023)
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
0