Show filters
1,232 Total Results
Displaying 211-220 of 1,232
Sort by:
Attacker Value
Unknown
CVE-2022-3213
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.
0
Attacker Value
Unknown
CVE-2022-1115
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.
0
Attacker Value
Unknown
CVE-2022-0284
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.
0
Attacker Value
Unknown
CVE-2021-3574
Disclosure Date: August 26, 2022 (last updated February 24, 2025)
A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.
0
Attacker Value
Unknown
CVE-2021-20224
Disclosure Date: August 25, 2022 (last updated February 24, 2025)
An integer overflow issue was discovered in ImageMagick's ExportIndexQuantum() function in MagickCore/quantum-export.c. Function calls to GetPixelIndex() could result in values outside the range of representable for the 'unsigned char'. When ImageMagick processes a crafted pdf file, this could lead to an undefined behaviour or a crash.
0
Attacker Value
Unknown
CVE-2022-2719
Disclosure Date: August 10, 2022 (last updated February 24, 2025)
In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.
0
Attacker Value
Unknown
CVE-2022-34258
Disclosure Date: August 09, 2022 (last updated February 24, 2025)
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
0
Attacker Value
Unknown
CVE-2022-34257
Disclosure Date: August 09, 2022 (last updated February 24, 2025)
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
0
Attacker Value
Unknown
CVE-2022-34255
Disclosure Date: August 09, 2022 (last updated February 24, 2025)
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to perform an account takeover for a victim. Exploitation of this issue does not require user interaction.
0
Attacker Value
Unknown
CVE-2022-34256
Disclosure Date: August 09, 2022 (last updated February 24, 2025)
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
0